AI Weekly Malaysia

Back to items Summaries

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

ID
23164
Status
summarized
Published
10 Sep 2026, 7:33 PM
Fetched
10 Sep 2026, 9:12 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
10 Sep 2026, 9:15 PM
Tags
Audience
developersai_agent_users

What happened

The Gigabud banking trojan (linked to the GoldFactory group) now installs a second app called Vwork that creates an Android work profile on infected phones, dropping a tampered banking app inside it. Because Android keeps work profiles isolated from the personal space, the real banking app's malware scan cannot detect the trojan sitting in the personal profile. Group-IB confirmed the full attack chain on devices in Indonesia; Vwork's architecture matches Shelter, an open-source app-isolation tool, but operated remotely by attackers instead of by the phone owner.

Why it matters

If you build or secure fintech/banking Android apps in Southeast Asia, your in-app malware detection logic likely only scans the profile it runs in—meaning a trojan in a separate work profile is invisible to it. The attack also abuses Accessibility permissions and overlay screens to capture credentials and run transactions under a black screen, so any SEA-facing banking app should treat Accessibility-enabled devices and work-profile installations as elevated risk signals.

Discussion angle

Should banking apps in Malaysia proactively detect and warn users when a work profile exists on the device, given that Gigabud has already been confirmed in Indonesia and uses government-portal phishing lures common across SEA?

Top