Caricamento…
  • September 11, 2026
  • Di aOneITForce

Gigabud Hides Banking Fraud Inside Android Work Profiles

Gigabud Hides Banking Fraud Inside Android Work Profiles

<p>The operators of the Gigabud banking trojan are abusing Android work profiles to create a hidden environment for fraudulent transactions. The technique uses a second application, known as Vwork, to establish a work profile and place a manipulated banking application inside it.</p><p>Work profiles are legitimate Android features commonly used to separate corporate applications and information from a person's private apps. That isolation becomes dangerous when controlled by malware. A banking application running inside the work profile may be unable to detect Gigabud operating in the personal profile, weakening security checks that normally search the device for malicious software.</p><h2>A Multi-Stage Mobile Attack</h2><p>Gigabud is distributed through applications impersonating airlines, government agencies, tax services and other trusted organizations. After installation, it requests powerful permissions, including Android Accessibility access, the ability to display content over other applications and permission to continue operating in the background.</p><p>Those capabilities let the malware inspect installed applications, place fake login screens over legitimate banking software and remotely control taps and keyboard input. Operators can reportedly conceal their actions behind a black screen while conducting transactions on the infected phone.</p><p>Vwork then creates the separate work environment. Its code appears to be derived from Shelter, a legitimate open-source application for isolating or duplicating Android apps. Security checks that normally limit which applications can control Shelter-like functions were reportedly removed, allowing Gigabud to direct the profile creation and launch applications within it.</p><h2>Confirmed Activity and Wider Targeting</h2><p>The complete chain has been confirmed on devices in Indonesia. Samples supporting the Vwork technique have also been associated with targeting in Brazil, Colombia, Egypt, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye and other markets, although samples alone do not prove successful infections.</p><p>Researchers observed roughly 1,469 compromised devices and 1,281 potentially compromised account logins in Indonesia between February and July 2026, with estimated losses approaching $960,000. Those figures represent only the activity visible to the researchers.</p><h3>What Users and Banks Should Do</h3><ul><li>Avoid installing applications from links, messages or unofficial stores.</li><li>Treat unexpected Accessibility permission requests as a serious warning.</li><li>Check Android account settings for an unfamiliar Work tab.</li><li>Look for briefcase badges on applications that should not be managed.</li><li>Contact the bank from a separate device if unauthorized profile activity is discovered.</li></ul><p>I believe mobile security teams must now treat Android profile boundaries as part of the attack surface. Isolation protects privacy only when the device owner or a trusted employer controls it. When malware becomes the profile administrator, the same boundary can divide security telemetry and help criminals hide fraudulent activity.</p>

Torna su