Gigabud's App Cloning Bypasses Fraud Alerts
Android malware clones banking apps into separate work profiles, letting fraudsters evade detection.
Fraudsters have found a new way to hide their tracks on Android devices by taking advantage of a legitimate feature designed for security. According to research from Group-IB, the banking trojan Gigabud can now clone a victim's banking app into a separate Android work profile, effectively severing the link between any malware alert and the fraudulent transaction that follows. This technique, detailed in research published on September 9, could give banks and security teams a run for their money.
Vwork Fills a Malicious Niche
Gigabud is not working alone. Group-IB's researchers say the trojan is being paired with Vwork, a weaponized fork of the open-source Android app cloning tool Shelter. This tailored tool grants Gigabud the ability to clone apps specifically for malicious purposes. The researchers attribute both Gigabud and Vwork to an actor known as GoldFactory, concluding that the group either developed or customized each component to work together seamlessly.
Vwork relies on Android's Work Profile feature, a system designed to create an isolated environment on a device. While Shelter is typically meant to be controlled by the device owner, Vwork takes a different approach. Group-IB says Vwork exposes its cloning functions as an interface that any other app on the device can call. This means that Gigabud, once installed, can trigger the cloning process without needing direct user interaction.
In essence, the attack involves installing malware on a victim's phone, then waiting for the right moment before cloning the bank's app into a fresh work profile. The fraudster then conducts transactions from that cloned environment. From the bank's perspective, the payment seems to originate from a new, unrecognized device with no history of malware, making it less likely to raise alarms.
Three Commands Enable Stealth Cloning
Gigabud samples that are built to work with Vwork contain dedicated code, including three new commands that allow the trojan to provision the work profile, clone a named app, and report back on what has been cloned. But cloning isn't just a simple tap; it requires a token from an external authorization server, which Gigabud retrieves. This added layer of complexity suggests that the operators are tech-savvy and have put considerable thought into ensuring their tool remains effective.
The main purpose of this cloning technique, according to Group-IB, is detection isolation. Apps residing in one Android profile are largely invisible to signature-based detection methods that operate in another. Therefore, if security software raises an alert in the personal profile, that alert may not trigger in the work profile created later. This separation is key to the evasion strategy employed by the fraudsters.
The full infection chain has only been confirmed on devices in Indonesia, but the threat is not limited to that region. Gigabud samples designed to work with Vwork were found to be targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye.
Malware's Evolution into Big Business
Gigabud itself is no stranger to mobile banking fraud. Active since 2022, it has been spreading through phishing sites, messengers, and social media platforms, often disguised as legitimate airline, tax authority, or government apps. Once installed, it requests accessibility access, overlay permission, and a battery exemption. The first of these is the most critical, as it give the operator a high level of control over the device.
Fake login screens are then used to capture banking credentials, while a separate invisible overlay takes the lock screen code. During the fraudulent activity itself, a black screen conceals what is happening on the handset, providing an added layer of stealth for the attacker.
The evolution of Gigabud to include app cloning through Vwork showcases the continuous innovation in the cybercrime ecosystem. By leveraging the same work profile feature that enterprises use to separate personal and work data on Android devices, the attackers have found a way to bypass certain security measures.
Indicators of Compromise Emerge
Group-IB's research provides some concrete numbers to underscore the scale of the problem. Between February and July 2026 in Indonesia, the researchers observed about 1,469 compromised devices and 1,281 potentially compromised logins. Estimated losses from these activities were roughly $960,939. However, the researchers are cautious, calling these figures indicative rather than representative of the broader region.
These numbers paint a picture of a persistent and active threat in Indonesia, but they also highlight the potential for the technique to be applied elsewhere. The targeting of 11 countries suggests that GoldFactory is looking to expand its operations or at least test the waters in various markets.
Six Behavioral Signals for Banks
In response to this evolving threat, Group-IB has identified six behavioral signals that banks and financial institutions can use to detect possible cloning attacks. These include the appearance of a work profile on a phone that the user never set up, matching markers of a banking app across multiple profiles, an otherwise empty isolated environment, and the presence of accessibility access on an app that has no legitimate reason for needing it.
The researchers advise that if two or more of these signals occur together, it should be treated as a high-risk session. Other recommendations include device binding to prevent stolen logins from authorizing payments, and for users, sticking to official app stores only.
As cybercriminals continue to adapt, these behavioral indicators can help security teams stay one step ahead, but they rely on constant vigilance and updating detection mechanisms to address new techniques like those used by Gigabud and Vwork.
Why This Matters for Fraud Detection
The introduction of app cloning into Gigabud's arsenal represents a significant shift in the tactics of mobile banking fraud. By isolating malicious activity in a separate work profile, attackers can potentially avoid triggering the same alarms that would normally catch a trojan operating in the personal profile. This could mean that banks and security vendors need to rethink their detection strategies, looking beyond simple signature-based methods and instead monitoring for behavioral anomalies that span across profiles.
For end users, this highlights the importance of installing apps only from official channels and being wary of any app that requests excessive permissions, especially accessibility services, without a clear reason. As Group-IB's research suggests, the combination of multiple warning signs can be a strong indicator of a compromised device.
Ultimately, the fight against mobile banking malware is becoming more complex, requiring a collaborative effort between security researchers, financial institutions, and users themselves.
Sources
- Infosecurity Magazine Original source
Continue Reading
WeChat worm exploited before calls answered
Tencent patches zero-click flaw that allowed account takeover via VoIP calls.
Fortinet Critical Patches Target JWT Bypass and Browser Proxy
Fortinet patches two critical flaws: one bypassing FortiMonitorOnSight auth via JWT, another allowing browser traffic proxy.
Alleged Chinese AI theft rings alarm bells
FBI, NSA and CISA warn of industrial-scale distillation campaigns targeting US frontier models.