Executive Summary

The Gigabud banking trojan has evolved its attack methodology by leveraging Android work profiles to evade detection by banking applications' security checks. Active since 2022 and attributed to the GoldFactory threat group, this remote access trojan now deploys a secondary app called Vwork that creates isolated work profiles on infected devices and installs tampered banking applications within them. By operating from within these separated environments, the trojan can conduct fraudulent transactions while remaining hidden from malware detection systems that scan the device's personal space. Group-IB confirmed active infections across Indonesia with estimated losses of $960,000 between February and July 2026, though the technique has been observed targeting multiple countries including Brazil, Colombia, Egypt, Mexico, and several Southeast Asian nations.

This incident represents a significant evolution in mobile banking malware, demonstrating how threat actors are adapting legitimate Android enterprise features for malicious purposes. As organizations increasingly rely on mobile banking and BYOD policies, understanding these sophisticated evasion techniques becomes critical for developing effective mobile security strategies.

Why This Matters Now

Mobile banking trojans are rapidly evolving to exploit legitimate OS features like Android work profiles, making traditional security detection methods insufficient. With mobile banking adoption accelerating globally and remote work increasing BYOD risks, organizations need immediate visibility into these advanced evasion techniques.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Gigabud uses a secondary app called Vwork to create isolated work profiles on infected devices, then installs tampered banking apps within these profiles where malware scans from the personal space cannot detect the trojan.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain the Gigabud banking trojan's ability to establish external communications and move laterally between network segments. Segmentation controls and egress enforcement could reduce the malware's operational reach and limit data exfiltration capabilities.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network-level visibility and policy enforcement may limit the trojan's ability to establish initial network connections and reduce its operational scope within segmented environments.

Privilege Escalation

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Identity-aware network controls may constrain the malware's ability to access network resources with elevated privileges and limit its operational capabilities across network segments.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation controls would likely limit the malware's ability to move between network segments and constrain its reach to additional systems or network resources.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Network visibility controls may detect and limit unauthorized external communications, constraining the malware's ability to receive commands and coordinate with operator infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely constrain data exfiltration pathways and reduce the volume of sensitive information transmitted to external operator infrastructure.

Impact (Mitigations)

Reduced network access scope and constrained communication channels may limit the scale of fraudulent transaction execution and decrease the overall financial impact across compromised devices.

Impact at a Glance

Affected Business Functions

  • Mobile Banking Services
  • Customer Account Management
  • Digital Payment Processing
  • Customer Support Operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $960,000

Data Exposure

Banking credentials, login information, and financial transaction data of approximately 1,469 compromised devices in Indonesia. The trojan captures keystrokes from banking apps and enables fraudulent transactions through remote access capabilities.

Recommended Actions

  • Implement Zero Trust segmentation to prevent unauthorized app installation and profile creation through identity-based policy enforcement
  • Deploy egress security controls to detect and block malicious command-and-control communications from mobile endpoints
  • Enable multicloud visibility and control capabilities to monitor anomalous mobile application behaviors and work profile creation
  • Establish threat detection and anomaly response systems to identify accessibility permission abuse and overlay attack patterns
  • Enforce encrypted traffic policies and secure connectivity frameworks to protect banking application data flows from interception

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image