Gigabud Trojans Hide in Android Work Profiles

A new tactic used by the Gigabud banking trojan is evading security checks by isolating malware within Android's work profile feature.
The Gigabud banking trojan has adopted a new method to evade detection on Android devices. According to a report by security firm Group-IB, the malware now installs a secondary application that creates a work profile on the phone. This profile acts as a separate digital space, traditionally used for employer apps, which isolates the malicious software from the rest of the system.
By placing a tampered version of a banking app inside this isolated profile, the trojan prevents the legitimate app’s internal security scans from detecting the threat. Banking apps typically check for known malware in the main user space, but the work profile remains invisible to these checks. This allows fraudulent transactions to occur without triggering alerts, effectively hiding the crime from the victim’s own security software.
Isolation Defeats Internal Scans
The technique relies on Android’s native ability to separate personal and work data. Group-IB explains that banking apps contain security code designed to look for known malware. However, this scan does not reach into the work profile where the trojan resides. Consequently, a fraudulent payment can appear unrelated to the alerts already raised in the main profile, confusing both the user and the device's defensive mechanisms.
The secondary application, identified as Vwork, is built using code similar to Shelter, an open-source tool that allows users to isolate apps manually. The critical difference is control. While Shelter is operated by the phone's owner, Vwork exposes its functions to other apps. This allows Gigabud to remotely drive Vwork, creating profiles and cloning apps without the user’s intent or knowledge.
Simplified Setup for Attackers
Legitimate tools like Shelter require a user to navigate through multiple screens to set up a work profile. Vwork bypasses this process, reducing it to a single prompt written in Chinese. Before cloning any apps, Vwork checks with an external server for permission, ensuring the actions are directed by the attacker. This streamlined process makes it easier for the trojan to deploy its payload quickly after initial infection.
Global Reach With Local Impact
Although the full chain of infection has been confirmed only in Indonesia, samples of Gigabud configured to work with Vwork have been found targeting Brazil, Colombia, Egypt, and several other countries. Group-IB noted that in the confirmed Indonesian cases, the app placed in the work profile was a fake version of a real local bank, not a copy of the victim’s own app. This suggests the attackers are tailoring their tools to specific regional banking systems.
The report highlights that while the technique is effective, the Vwork sample analyzed is still under development, with some functions proving unstable on certain Android versions. Users in targeted regions should remain cautious of apps requesting Accessibility access or drawing over other apps, as these permissions are often used to gain full control of the device. The primary risk remains the combination of remote access and the ability to hide malicious activity within system-level profiles.






