Executive Summary
The Gigabud banking trojan has evolved its attack methodology by leveraging Android work profiles to evade detection by banking applications' security checks. Active since 2022 and attributed to the GoldFactory threat group, this remote access trojan now deploys a secondary app called Vwork that creates isolated work profiles on infected devices and installs tampered banking applications within them. By operating from within these separated environments, the trojan can conduct fraudulent transactions while remaining hidden from malware detection systems that scan the device's personal space. Group-IB confirmed active infections across Indonesia with estimated losses of $960,000 between February and July 2026, though the technique has been observed targeting multiple countries including Brazil, Colombia, Egypt, Mexico, and several Southeast Asian nations.
This incident represents a significant evolution in mobile banking malware, demonstrating how threat actors are adapting legitimate Android enterprise features for malicious purposes. As organizations increasingly rely on mobile banking and BYOD policies, understanding these sophisticated evasion techniques becomes critical for developing effective mobile security strategies.
Why This Matters Now
Mobile banking trojans are rapidly evolving to exploit legitimate OS features like Android work profiles, making traditional security detection methods insufficient. With mobile banking adoption accelerating globally and remote work increasing BYOD risks, organizations need immediate visibility into these advanced evasion techniques.
Attack Path Analysis
Gigabud banking trojan infects Android devices through fake apps posing as government services, gains accessibility permissions for device control, then deploys Vwork to create isolated work profiles where tampered banking apps operate undetected. The malware captures credentials through overlay attacks, executes fraudulent transactions via accessibility controls, and exfiltrates banking data while evading detection through Android's profile isolation mechanisms.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Victims install fake apps impersonating national airlines, tax offices, or government portals distributed outside official app stores, leading to Gigabud trojan installation
MITRE ATT&CK® Techniques
Deliver Malicious App via Non-Application Store
Download New Code at Runtime
Input Capture
Capture SMS Messages
Gathering Victim Host Information
Input Injection
Code Injection
Application Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques for Bespoke and Custom Software
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Enterprise Manages All Identities
Control ID: Identity-1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Direct target of Gigabud mobile banking trojan using Android work profiles to bypass security checks, enabling fraudulent transactions and credential theft.
Financial Services
Mobile banking applications vulnerable to work profile isolation attacks that circumvent malware detection, compromising transaction integrity and customer authentication.
Telecommunications
Android platform security weaknesses exploited through accessibility permissions and work profile manipulation, requiring enhanced mobile device management and monitoring capabilities.
Government Administration
Government portals and tax office applications impersonated in initial infection vector, creating citizen identity theft risks and undermining public service trust.
Sources
- Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checkshttps://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.htmlVerified
- VWork App Cloning: How Gigabud Exploits Android Work Profileshttps://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/Verified
- Android Enterprise Managed Profiles Documentationhttps://source.android.com/docs/devices/admin/managed-profilesVerified
- Google Work Profile User Guidehttps://support.google.com/work/android/answer/6191949Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain the Gigabud banking trojan's ability to establish external communications and move laterally between network segments. Segmentation controls and egress enforcement could reduce the malware's operational reach and limit data exfiltration capabilities.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network-level visibility and policy enforcement may limit the trojan's ability to establish initial network connections and reduce its operational scope within segmented environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Identity-aware network controls may constrain the malware's ability to access network resources with elevated privileges and limit its operational capabilities across network segments.
Control: East-West Traffic Security
Mitigation: Microsegmentation controls would likely limit the malware's ability to move between network segments and constrain its reach to additional systems or network resources.
Control: Multicloud Visibility & Control
Mitigation: Network visibility controls may detect and limit unauthorized external communications, constraining the malware's ability to receive commands and coordinate with operator infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain data exfiltration pathways and reduce the volume of sensitive information transmitted to external operator infrastructure.
Reduced network access scope and constrained communication channels may limit the scale of fraudulent transaction execution and decrease the overall financial impact across compromised devices.
Impact at a Glance
Affected Business Functions
- Mobile Banking Services
- Customer Account Management
- Digital Payment Processing
- Customer Support Operations
Estimated downtime: N/A
Estimated loss: $960,000
Banking credentials, login information, and financial transaction data of approximately 1,469 compromised devices in Indonesia. The trojan captures keystrokes from banking apps and enables fraudulent transactions through remote access capabilities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to prevent unauthorized app installation and profile creation through identity-based policy enforcement
- • Deploy egress security controls to detect and block malicious command-and-control communications from mobile endpoints
- • Enable multicloud visibility and control capabilities to monitor anomalous mobile application behaviors and work profile creation
- • Establish threat detection and anomaly response systems to identify accessibility permission abuse and overlay attack patterns
- • Enforce encrypted traffic policies and secure connectivity frameworks to protect banking application data flows from interception



