#GigaBud
¡Gracias por compartir! Gigabud es peligroso porque abusa de los perfiles de trabajo. Recuerda: solo instala apps desde la Play Store oficial y desconfía de permisos inusuales. ¡Mantente seguro!
October 1, 2026 at 3:15 PM
Gigabud y los perfiles de trabajo: El troyano que dobla las reglas de Android para vaciar cuentas www.disoftin.com/2026/09/giga...
Gigabud y los perfiles de trabajo: El troyano que dobla las reglas de Android para vaciar cuentas
Blog sobre seguridad de la informacion, ethical hacking, pentest
www.disoftin.com
September 28, 2026 at 3:28 PM
Giga Bud won’t be in stock forever. 👀🌱
##PacificSeedBank #GigaBud #HomeGrow #GrowFromSeed #GrowYourOwn #SeedBank
September 21, 2026 at 4:42 PM
Gigabud, troyano bancario para Android: no roba la app de tu banco, la copia en un perfil de trabajo y la seguridad del banco no lo ve. México está entre sus objetivos (sin víctimas confirmadas). ¿Apps con un maletín que no pusiste? Es un perfil de trabajo. Fuente: Group-IB, 9-sep
September 15, 2026 at 3:00 AM
Un programa malicioso crea una copia oculta de tu aplicación bancaria.

Vía: @malwarebytes.com
Android Un programa malicioso crea una copia oculta de tu aplicación bancaria.
El troyano bancario Gigabud puede clonar una aplicación bancaria en un perfil de trabajo separado en un Android dispositivo para ayudar a ocultar transacciones fraudulentas.
www.malwarebytes.com
September 14, 2026 at 4:01 AM
Group-IB found the Gigabud banking Trojan clones a victim's banking app into a separate Android work profile, letting attackers transact while malware alerts stay in the personal profile.
Gigabud Android Trojan Clones Banking Apps Into Separate Work Profile
Group-IB found the Gigabud banking Trojan clones a victim's banking app into a separate Android work profile, letting attackers transact while malware alerts stay in the personal profile.
www.technobezz.com
September 12, 2026 at 6:15 PM
La clonación de aplicaciones bancarias implica la duplicación no autorizada de aplicaciones legítimas para robar información sensible.

https://norvik.tech/news/analisis-gigabud-vwork-clonacion-banco-android
September 12, 2026 at 7:05 AM
Gigabud / Vwork: Account Takeover via Android Banking App Cloning in Work Profiles
## 1. Basic Information * Original Title: Indonesia Hit by Android Banking App Cloning Campaign * Source: Dark Reading, Group-IB * Publication Date: 2026-09-11 * Severity: High * Basis for Severity: Actual financial losses and numerous compromised devices have been confirmed, and the enterprise Work Profile feature is being abused to isolate and evade detection in consumer banking fraud. * Original Link: Indonesia Hit by Android Banking App Cloning Campaign * Related Sources: Group-IB: Vwork App Cloning in Gigabud/GoldFactory, MITRE ATT&CK: Device Administrator Permissions * Related Malware: Gigabud, Vwork * Related Threat Group: GoldFactory * Related Products: Android, Android Work Profile, mobile banking applications ## 2. Executive Summary Gigabud obtains accessibility permissions, deploys Vwork, and clones banking apps inside an Android Work Profile. It leverages the separation from the personal profile to register the device with the bank, enabling remote control and unauthorized fund transfers behind a black screen. ## 3. Attack Flow ### Flow 1: Banking App Cloning Using Vwork via Gigabud 1. The victim sideloads an APK disguised as an airline, tax, or government app. 2. Gigabud requests accessibility permissions, display over other apps, and ignore battery optimizations. It collects credentials through a fake banking login screen and screen lock codes through another mechanism. 3. C2 commands deploy Vwork and create an Android Work Profile. 4. Vwork clones the banking app into the Work Profile, and Gigabud relays operation commands. Group-IB's confirmed examples also include deploying modified versions disguised as legitimate banking apps. 5. The attacker registers the cloned app as a new device behind a black screen overlay and transfers funds without authorization. ## 4. Attacker Positioning and Execution Location * External attacker who induces the victim to sideload the APK and grant permissions. * Once permissions are obtained, the attacker remotely controls the device screen and apps, operating the banking apps within the Work Profile. ## 5. Visibility for Victims and Administrators ### Victims * Requests to install fake brand apps, permission prompts for accessibility, display over other apps, and ignore battery optimizations. * Unexpected briefcase icon for the Work Profile, duplicated banking apps, and a black screen during operation. ### Administrators * APKs from unofficial sources, `net.yy.vwork`, rapid Work Profile creation, and banking app cloning. * Linking of new profiles and new devices from the same physical device, along with unusual transfers. ## 6. Success and Failure Conditions ### Success Conditions * The user sideloads the malicious APK and grants accessibility and other permissions. * The device allows the creation of a Work Profile and the cloning of banking apps. * The bank does not carry over personal profile risk signals to the authentication of the new profile. ### Failure Conditions * Inference: Restricting APK installation from external sites and unauthorized app permissions via device policies can block the reported delivery vector. * Inference: On managed devices, restrict unauthorized accessibility usage and Work Profile creation based on MDM capabilities. * Inference: Linking new device registration and transfer risk assessments on the bank side, and requiring additional authentication when necessary, can curb misuse after app cloning. ## 7. What Happens Upon Success * Theft of mobile banking credentials and transaction authentication. * Remote control and unauthorized fund transfers that are hard for the user to notice. * Inference: The same technique may be repurposed for other banking and payment apps. The targets and scope of success depend on the app and bank controls. ## 8. Observable Logs ### Email * Group-IB reports APK distribution via social engineering such as SMS. Review messages and URLs provided by users. May not appear in corporate email logs. ### Proxy / SWG / DNS * Inference: Communications to fake airline, tax, and government domains, Gigabud C2, and APK download sources. ### Endpoint / EDR * Inference: Deployment of `net.yy.vwork`, accessibility service registration, overlays, ignoring battery optimizations, Work Profile creation, and app cloning. ### Identity / IdP * Inference: Check new device registrations, changes in authentication methods, and login origins in bank records. The mapping between physical devices and profiles depends on available identifiers and bank cooperation. ### SaaS / Cloud * Inference: New device registration for mobile banking, adding recipients and making transfers inconsistent with user behavior. ### Network * Inference: C2 where Gigabud relays Vwork commands, and continuous communication associated with remote screen control. ## 9. Attack Success Criteria Below are the ranges confirmed by public information and the determination criteria used in internal investigations. * **User Action Confirmed** : Public Info: Gigabud distribution utilizes APK installation from external sites and permission grants. Group-IB has confirmed the infection vector on the device. * **Initial Execution Confirmed** : Public Info: The deployment of Vwork and banking apps following Gigabud, using Work Profiles, has been reported. * **Information Theft or Session Compromise Confirmed** : Public Info: Credential theft via fake login screens has been reported. The 1,281 cases represent potentially compromised logins and not confirmed unauthorized transfer counts. * **Subsequent Compromise Confirmed** : Public Info: Group-IB reported banking operations on victim devices and estimated losses. Individual cases require confirmed unauthorized transfers in bank transaction records, and APK deployment or profile creation alone does not constitute successful transfer. ## 10. Investigation Playbook ### Triggers * Granting accessibility to an unknown APK, `net.yy.vwork`, unexpected Work Profile, or duplicated banking apps. ### Initial Response * Preserve the APK acquisition path, package, signature, permissions, profile creation time, and bank login time. ### Device / Server * Check Android package lists, accessibility services, device policy management apps, overlays, Work Profiles, and ignored battery optimizations. ### Authentication / Cloud * Investigate bank-side device IDs, profiles, device bindings, login IPs, added recipients, and transfer history. ### Subsequent Operations * Inference: Check for additional APKs, cloning of other banking and wallet apps, and access permissions/usage traces for SMS. Notification theft is not treated as a confirmed behavior in this material. ### Containment * Isolate the device from the network, contact the bank to invalidate sessions, device bindings, and credentials. * Preserve evidence, and wipe/re-enroll corporate devices according to management procedures. Check other devices using the same account. ### Determination Categories * Separate APK contact, permission grants, Work Profile creation, successful bank authentication, and unauthorized transfers. ## 11. Defense and Detection Ideas ### Single Event * Inference: Work Profile creation on non-MDM managed devices, or detection of `net.yy.vwork`. * Inference: Simultaneous grant of accessibility and overlay permissions to an unknown app. ### Time-Series Correlation * Inference: Correlate sideloading -> accessibility -> Vwork -> profile creation -> banking app cloning -> new device authentication -> transfer. ### Hunting * Inference: Enumerate Work Profile creation sources, cloned high-value apps, and abnormal accessibility services across Android device fleets. ### Log Gaps * When bank-side and device-side records cannot be correlated, it becomes difficult to confirm whether different profiles belong to the same physical device or to establish the link between registration and transfer. ### Priority Countermeasures * Inference: Prioritize blocking sideloading, accessibility allowlists, Work Profile management, and integrating financial-side device bindings. ## 12. Facts / Inference / Hypothesis ### Facts * Group-IB reported approximately 1,469 compromised devices, 1,281 potentially compromised logins, and an estimated $960,000 in losses observed in Indonesia between February and July 2026. These values reflect Group-IB's observation scope and do not represent the total regional damage scale. * Gigabud is distributed as fake airline, tax, and government apps outside official stores, and requests accessibility, display over other apps, and ignore battery optimizations. * Minutes after installation, Gigabud deploys Vwork (`net.yy.vwork`) and operates it using C2 commands such as `initVwa`, `cloneApp`, and `uploadCloneApps`. * Vwork is a modified version of the open-source tool Shelter, which clones target banking apps into a Work Profile. Vwork itself has no C2, and Gigabud relays its commands. * Attackers remotely operate the cloned apps behind a black screen overlay, appearing to the bank as a new device and new profile. ### Inference * If infection, overlay, and accessibility signals from the personal profile are not shared with the banking app assessment in the Work Profile, traditional device-level rules may be bypassed. * Time-series detection spanning Work Profile creation, app cloning, device registration, and fund transfers is effective. ### Hypothesis No additional hypotheses. Unconfirmed items are listed in "Unanswered Questions and Further Investigation". ## 13. MITRE ATT&CK Mapping * **T1660 Phishing** (Confidence: high): Induces deployment using fake airline, tax, and government apps. * **T1406.002 Obfuscated Files or Information: Software Packing** (Confidence: medium): Group-IB reports that both Vwork and related Gigabud samples are packed with dpt-shell. * **T1626.001 Abuse Elevation Control Mechanism: Device Administrator Permissions** (Confidence: medium): Group-IB reports that Vwork and Gigabud request device administrator privileges. This is a separate behavior from the abuse of accessibility permissions. * **T1453 Abuse Accessibility Features** (Confidence: high): Uses accessibility as the foundation for screen operation, information retrieval, and remote control. ## 14. Unanswered Questions and Further Investigation * Target app lists and financial losses by country and bank. * Specific conditions for bypassing biometric authentication and device bindings inside Work Profiles. * Vwork detection status by Google Play Protect and major MDMs. * Correlation between the 1,469 compromised devices and 1,281 potentially compromised logins, as well as the success count of unauthorized transfers. Due to differing aggregation units, transfer success rates cannot be determined from the difference between the two. ## 15. Impact on SOCs and Organizations For domestic organizations utilizing Work Profiles, unauthorized profile creation and app deployment are subject to investigation. Mobile SOCs should review available device, permission, and profile records, and cross-reference them with bank-side device registration and transaction records if unauthorized transfers are suspected. This report does not confirm that damage from the same attack has been observed in Japan. ## 16. Summary by Role * **SOC** : Correlate Gigabud deployment, `net.yy.vwork`, Work Profile creation, target app cloning, black screen overlays, and subsequent new device logins. * **Administrators** : Block APKs from outside official stores and restrict accessibility, overlays, and Work Profile creation for unknown apps via MDM. * **Users** : Avoid sideloading apps masquerading as airlines, tax services, or government agencies from external sites, and report unexpected Work Profile displays or duplicated banking apps.
dev.to
September 12, 2026 at 1:33 AM
Making cybercrime more difficult.

The FBI has released its inaugural cyber strategy, emphasizing disruption of threat actors. CISA is planning a comprehensive federal cyber overhaul with new support contracts. Anthropic has reported a fourth instance of unauthoriz…
#anthropic #hackernews #microsoft
Making cybercrime more difficult.
The FBI has released its inaugural cyber strategy, emphasizing disruption of threat actors. CISA is planning a comprehensive federal cyber overhaul with new support contracts. Anthropic has reported a fourth instance of unauthorized intrusion into its AI systems. The U.S. Treasury Department has sanctioned a Chinese online marketplace for cybercrime activities. A new Microsoft Defender zero-day vulnerability, dubbed "ShieldCrash," has been identified. The Gigabud banking malware is becoming more sophisticated by employing app cloning for stealth. Chinese espionage groups are reportedly using the BlueMoon exploit kit, which targets Chrome and Windows. Lawmakers are taking action against hack-for-hire firms, requesting a ban on several. An Italian technology collective has ceased operations following a U.S. designation. Private conversations within AI chatbots are increasingly being introduced as evidence in legal proceedings.
www.thecyberwire.com
September 11, 2026 at 8:32 PM
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 11, 2026 at 6:51 PM
Indonesia Hit by Android Banking App-Cloning Campaign https://bit.ly/4hmKk7R by Alexander Culafi #DRGlobal
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
www.darkreading.com
September 11, 2026 at 4:45 PM
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection #AndroidTrojanxaBankingScam #AppCloningxaCyberFraud #Gigabud
Gigabud Android Trojan Uses App Cloning to Evade Fraud Detection
 A new report says the Gigabud Android banking trojan has evolved to clone banking apps into a separate work profile, helping criminals evade fraud detection and make stolen transactions look like they came from a clean device. Group-IB says the campaign combines Gigabud with a weaponized app-cloning tool called Vwork, which it links to the GoldFactory group.  Gigabud is not a new threat, but this latest version shows how mobile banking fraud is becoming more sophisticated. The malware reportedly uses Android’s Work Profile feature to isolate a cloned banking app from the user’s personal profile, which can break the connection between a malware alert and the later payment activity.  According to the report, Vwork exposes cloning functions through an interface that other apps on the device can call, making it easier for Gigabud to automate the attack. The trojan includes commands to provision the profile, clone a target app, and report back what was copied, while requiring a token from an external authorization server before cloning begins. The fraud chain was confirmed on devices in Indonesia, where Group-IB observed about 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026, with estimated losses of roughly $960,939. The samples were also found targeting 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye.  To reduce risk, Group-IB recommends that banks watch for warning signs such as a work profile appearing on a phone the customer never configured, matching app markers across profiles, and suspicious accessibility access on apps that should not need it. For users, the safest habit is to install apps only from official stores and avoid suspicious links delivered through phishing sites, messengers, or social media.
dlvr.it
September 11, 2026 at 4:16 PM
Researchers found that the Android banking Trojan Gigabud can create a separate work profile and install a cloned banking app inside it. This allows attackers to make fraudulent transactions while potentially hiding their activity from malware detection on the main profile.
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
bit.ly
September 11, 2026 at 3:16 PM
Malware clona app bancaria en perfil de trabajo en Android

El malware Gigabud crea una copia oculta de la app bancaria en un perfil de trabajo…

https://mentehackers.com/malware-clona-app-bancaria-en-perfil-de-trabajo-en-android-c16b12e7
#Ciberseguridad #Android #Tecnologia
Malware clona app bancaria en perfil de trabajo en Android
El malware Gigabud crea una copia oculta de la app bancaria en un perfil de trabajo. Esto permite fraudes sin ser detectados por sistemas de seguridad.
mentehackers.com
September 11, 2026 at 2:33 PM
Gigabudがバンキング詐欺を隠すためにAndroidの職場プロファイルを悪用

個人用アプリと業務用アプリを分離するために設計されたAndroidの機能が、バンキング詐欺の隠れ蓑になっています。Group-IBは、GigabudとVworkの組み合わせについて説明しており、確認された攻撃連鎖では、職場プロファイルを作成し、その中に偽の銀行アプリを配置したうえで、1台のデバイス
Gigabudがバンキング詐欺を隠すためにAndroidの職場プロファイルを悪用
個人用アプリと業務用アプリを分離するために設計されたAndroidの機能が、バンキング詐欺の隠れ蓑になっています。Group-IBは、GigabudとVworkの組み合わせについて説明しており、確認された攻撃連鎖では、職場プロファイルを作成し、その中に偽の銀行アプリを配置したうえで、1台のデバイス
blackhatnews.tokyo
September 11, 2026 at 2:06 PM
Gigabud clones your banking app into a hidden Android work profile invisible to fraud detection. https://intel.threadlinqs.com/threat/TL-2026-2444 #ThreatIntel #Gigabud #GoldDigger #GoldDiggerPlus
September 11, 2026 at 12:54 PM
Androidマルウェア、銀行アプリの隠しコピーを作成

Group-IBの調査によると、Androidバンキング型トロイの木馬「Gigabud」は、感染したスマートフォン上に別のワークプロファイルを作成し、その中でクローンされた銀行アプリを実行できることが分かりました。攻撃者はこの新しいプロファイル内で不正な取引を実行でき、デバイスの他の場所で検出されたマルウェアの痕...
Androidマルウェア、銀行アプリの隠しコピーを作成
Group-IBの調査によると、Androidバンキング型トロイの木馬「Gigabud」は、感染したスマートフォン上に別のワークプロファイルを作成し、その中でクローンされた銀行アプリを実行できることが分かりました。攻撃者はこの新しいプロファイル内で不正な取引を実行でき、デバイスの他の場所で検出されたマルウェアの痕
blackhatnews.tokyo
September 11, 2026 at 12:46 PM
Android malware creates a hidden copy of your banking app. Malwarebytes Labs: www.malwarebytes.com/blog/mobile/...
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
www.malwarebytes.com
September 11, 2026 at 12:17 PM
⚠️ Gigabud malware uses Android work profiles to bypass security checks, risking your finances. Know more? https://gigcitygeek.com/237264
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
gigcitygeek.com
September 11, 2026 at 12:09 PM