#GigaBud
Gigabud y los perfiles de trabajo: El troyano que dobla las reglas de Android para vaciar cuentas www.disoftin.com/2026/09/giga...
Gigabud y los perfiles de trabajo: El troyano que dobla las reglas de Android para vaciar cuentas
Blog sobre seguridad de la informacion, ethical hacking, pentest
www.disoftin.com
September 28, 2026 at 3:28 PM
Still at work you goons. What’s the real lineage for Gigabud oh wise one?
May 15, 2026 at 6:45 PM
-CL-CRI-1171 runs PPI platform
-New DENOmination Group profile
-Passkey-themed campaign
-CEO impersonation campaign
-New Gigabud Android banking trojan
-Russian APT deploys DarkSword against NATO targets
-Four APTs used the same exploit kit
-Another Chrome zero-day
-ShieldCrash zero-day
September 11, 2026 at 8:09 AM
July 24, 2025 at 10:03 PM
@mikelowetpt.bsky.social Gigabud. Lots of conflicting lineage takes out there. I’ve seen G13xNorthen Lights, G13xBig Bud, and Norther LightsxBig Bud. Idk which one it is but I can’t wait to get home and try it.
May 15, 2026 at 4:18 PM
Researchers found that the Android banking Trojan Gigabud can create a separate work profile and install a cloned banking app inside it. This allows attackers to make fraudulent transactions while potentially hiding their activity from malware detection on the main profile.
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
bit.ly
September 11, 2026 at 3:16 PM
Midtjylland er altså klar til å legge inn bud på 11 millioner euro på er ettertraktet stortalent i Argentina som de største klubbene i Europa er ute etter. De jobber på en helt annen hylle med helt andre rammer enn oss..

bold.dk/fodbold/klub...
FCM klar med gigabud på argentinsk guldfugl
FC Midtjylland er ifølge Bolds oplysninger klar til at lægge et bud på omkring 11 mio. euro for den argentinske offensivspiller Maher Carrizo, som også Manchester City meldes interesseret i.
bold.dk
January 17, 2026 at 6:38 PM
Giga Bud won’t be in stock forever. 👀🌱
##PacificSeedBank #GigaBud #HomeGrow #GrowFromSeed #GrowYourOwn #SeedBank
September 21, 2026 at 4:42 PM
Greit salg av Denzel. Meget verre å miste folk i sentralinjen Frykter noen gigabud på Noah da. Nå som han putter titt og ofte er han rett og slett en komplett spiss som større klubber vil sikle etter. Men med en nyfødt kan man vel håpe han har mest lyst å gi alt for Brann hvertfall kommende sesong.
August 27, 2026 at 8:38 PM
GoldFactory、東南アジアで改ざんされた銀行アプリを使い11,000件以上の感染を引き起こす

GoldFactoryとして知られる金銭目的のグループに関連するサイバー犯罪者が、インドネシア、タイ、ベトナムのモバイルユーザーを標的に、政府サービスを装って新たな攻撃を仕掛けていることが確認されました。 2024年10月以降に観測された活動は、改ざんされた銀行アプリケーションを配布し、Androidマルウェアの媒介として機能させるものだと、Group-IBは水曜日に発表した技術レポートで述べています。…
GoldFactory、東南アジアで改ざんされた銀行アプリを使い11,000件以上の感染を引き起こす
GoldFactoryとして知られる金銭目的のグループに関連するサイバー犯罪者が、インドネシア、タイ、ベトナムのモバイルユーザーを標的に、政府サービスを装って新たな攻撃を仕掛けていることが確認されました。 2024年10月以降に観測された活動は、改ざんされた銀行アプリケーションを配布し、Androidマルウェアの媒介として機能させるものだと、Group-IBは水曜日に発表した技術レポートで述べています。 2023年6月にはすでに活動していたと評価されているGoldFactoryは、昨年初めに初めて注目を集めました。シンガポールに本社を置くサイバーセキュリティ企業が、GoldPickaxe、GoldDigger、GoldDiggerPlusなどのカスタムマルウェアファミリーを使い、AndroidおよびiOSデバイスの両方を標的にした脅威アクターの手口を詳述しました。 証拠によると、GoldFactoryは中国語を話すサイバー犯罪グループで、Gigabudという2023年中頃に発見された別のAndroidマルウェアと密接な関係があるとみられています。コードベースには大きな違いがあるものの、GoldDiggerとGigabudはいずれも偽装ターゲットやランディングページに類似点が見られます。 最新の攻撃波の最初の事例はタイで検出され、その後2024年末から2025年初頭にかけてベトナム、2025年中頃からはインドネシアでも脅威が現れました。 Group-IBによると、インドネシアで2,200件近い感染を引き起こした改ざん銀行アプリのユニークなサンプルを300件以上特定したとのことです。さらに調査を進めた結果、11,000件以上の感染につながったとされる3,000件超のアーティファクトも発見されました。改ざんされた銀行アプリの約63%はインドネシア市場向けです。 感染チェーンの概要としては、政府機関や信頼されたローカルブランドを装い、電話でターゲットに接触し、Zaloなどのメッセージアプリで送信したリンクをクリックさせてマルウェアをインストールさせる手口です。 Group-IBが記録した少なくとも1件の事例では、詐欺師がベトナムの公営電力会社EVNを装い、被害者に未払いの電気料金を支払うよう促し、支払わなければ即時サービス停止のリスクがあると脅しました。通話中、脅威アクターは被害者にZaloで連絡を取るよう求め、アプリのダウンロードリンクとアカウント連携のための案内を送りました。 リンクは被害者を偽のランディングページにリダイレクトし、Google Playストアのアプリリストを装っています。その結果、Gigabud、MMRat、Remoなどのリモートアクセス型トロイの木馬が展開されます。これらはGoldFactoryと同じ手口で今年初めに登場しました。これらのドロッパーは、Androidのアクセシビリティサービスを悪用してリモート操作を可能にするメインペイロードの導入につながります。 「このマルウェアは[...]元のモバイルバンキングアプリケーションをベースにしています」と研究者のAndrey Polovinkin、Sharmine Low、Ha Thi Thu Nguyen、Pavel Naumovは述べています。「アプリケーションの一部にのみ悪意のあるコードを注入することで動作し、元のアプリケーションの通常機能は維持されます。注入された悪意のあるモジュールの機能はターゲットごとに異なる場合がありますが、主に元のアプリケーションのセキュリティ機能を回避します。」 具体的には、アプリケーションのロジックにフックしてマルウェアを実行します。改ざんアプリでランタイムフックを行うために使用されるフレームワークに基づき、FriHook、SkyHook、PineHookという3種類のマルウェアファミリーが発見されています。これらの違いに関わらず、モジュールの機能は重複しており、次のことが可能です。 アクセシビリティサービスが有効なアプリ一覧を隠す 画面キャスト検出を防ぐ Androidアプリの署名を偽装する インストール元を隠す カスタムインテグリティトークンプロバイダーを実装する 被害者の口座残高を取得する SkyHookは公開されているDobbyフレームワークを使ってフックを実行し、FriHookはFridaガジェットを正規の銀行アプリに注入して利用します。PineHookはその名の通り、PineというJavaベースのフックフレームワークを使っています。 Group-IBによると、GoldFactoryが構築した悪意のあるインフラを分析した結果、Gigabudマルウェアの後継とみられる新たなAndroidマルウェア「Gigaflower」のプレリリーステストビルドも発見されました。 このマルウェアは約48種類のコマンドをサポートしており、WebRTCを使ったリアルタイムの画面・デバイスアクティビティのストリーミング、アクセシビリティサービスを悪用したキーロギングやユーザーインターフェース内容の読み取り、ジェスチャーの実行、システムアップデートやPIN入力、アカウント登録を模倣した偽画面の表示による個人情報の収集、内蔵の文字認識アルゴリズムを使った身分証画像からのデータ抽出などが可能です。 現在開発中の機能としては、ベトナムの身分証明書上のQRコードを読み取るQRコードスキャナーがあり、詳細情報の取得プロセスを簡素化することが目的とみられます。 興味深いことに、GoldFactoryは独自のiOSトロイの木馬を捨て、被害者に家族や親戚からAndroid端末を借りて手続きを続けるよう指示するという、これまでにない手法を採用しているようです。この方針転換の理由は明らかではありませんが、iOSのセキュリティ強化やアプリストアの審査厳格化が背景にあると考えられています。 「以前のキャンペーンがKYCプロセスの悪用に焦点を当てていたのに対し、最近の活動では正規の銀行アプリケーションを直接改ざんして詐欺を行っています」と研究者らは述べています。「Frida、Dobby、Pineなどの正規フレームワークを使って信頼された銀行アプリを改ざんする手法は、高度かつ低コストで、従来の検知を回避しつつサイバー犯罪者が迅速に活動を拡大できることを示しています。」 翻訳元:
blackhatnews.tokyo
December 4, 2025 at 9:40 AM
Gigabud, troyano bancario para Android: no roba la app de tu banco, la copia en un perfil de trabajo y la seguridad del banco no lo ve. México está entre sus objetivos (sin víctimas confirmadas). ¿Apps con un maletín que no pusiste? Es un perfil de trabajo. Fuente: Group-IB, 9-sep
September 15, 2026 at 3:00 AM
Un programa malicioso crea una copia oculta de tu aplicación bancaria.

Vía: @malwarebytes.com
Android Un programa malicioso crea una copia oculta de tu aplicación bancaria.
El troyano bancario Gigabud puede clonar una aplicación bancaria en un perfil de trabajo separado en un Android dispositivo para ayudar a ocultar transacciones fraudulentas.
www.malwarebytes.com
September 14, 2026 at 4:01 AM
Group-IB found the Gigabud banking Trojan clones a victim's banking app into a separate Android work profile, letting attackers transact while malware alerts stay in the personal profile.
Gigabud Android Trojan Clones Banking Apps Into Separate Work Profile
Group-IB found the Gigabud banking Trojan clones a victim's banking app into a separate Android work profile, letting attackers transact while malware alerts stay in the personal profile.
www.technobezz.com
September 12, 2026 at 6:15 PM
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection #AndroidTrojanxaBankingScam #AppCloningxaCyberFraud #Gigabud
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection
 A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud detection and make stolen transactions look like they came from a clean device. Group-IB says the campaign combines Gigabud with a weaponized app-cloning tool called Vwork, which it links to the GoldFactory group.  Gigabud is not a new threat, but this latest version shows how mobile banking fraud is becoming more sophisticated. The malware reportedly uses Android’s Work Profile feature to isolate a cloned banking app from the user’s personal profile, which can break the connection between a malware alert and the later payment activity.  According to the report, Vwork exposes cloning functions through an interface that other apps on the device can call, making it easier for Gigabud to automate the attack. The trojan includes commands to provision the profile, clone a target app, and report back what was copied, while requiring a token from an external authorization server before cloning begins. The fraud chain was confirmed on devices in Indonesia, where Group-IB observed about 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026, with estimated losses of roughly $960,939. The samples were also found targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye.  To reduce risk, Group-IB recommends that banks watch for warning signs such as a work profile appearing on a phone the customer never configured, matching app markers across profiles, and suspicious accessibility access on apps that should not need it. For users, the safest habit is to install apps only from official stores and avoid suspicious links delivered through phishing sites, messengers, or social media.
dlvr.it
September 11, 2026 at 4:16 PM
Gigabud clones your banking app into a hidden Android work profile invisible to fraud detection. https://intel.threadlinqs.com/threat/TL-2026-2444 #ThreatIntel #Gigabud #GoldDigger #GoldDiggerPlus
September 11, 2026 at 12:54 PM
La clonación de aplicaciones bancarias implica la duplicación no autorizada de aplicaciones legítimas para robar información sensible.

https://norvik.tech/news/analisis-gigabud-vwork-clonacion-banco-android
September 12, 2026 at 7:05 AM
⚠️ Gigabud malware uses Android work profiles to bypass security checks, risking your finances. Know more? https://gigcitygeek.com/237264
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
gigcitygeek.com
September 11, 2026 at 12:09 PM
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 11, 2026 at 6:51 PM