← Back to feed
Threat Actors & CampaignsEmerging2 sourcesSep 11, 2026 · 12:14via Malwarebytes Labs

Android malware creates a hidden copy of your banking app

Brief

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter . Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.

The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there.

Read more on Malwarebytes Labs→

All credited sources

Highest-trust first. Dates are the publisher's original publish time.

Malwarebytes LabsPrimary··trust 1.28

Android malware creates a hidden copy of your banking app

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter . Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely.

The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there. Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles.

Android work profiles are normally used to keep work apps and data separate from personal ones. Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile.

How an attack works

Victims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.

To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays .

The sideloaded app checks which other apps are installed and tells the operator which relevant banking targets are present.

Fake banking-login overlays steal both banking credentials and the device’s PIN.

Read more →
Malware.news··trust 0.88

Android malware creates a hidden copy of your banking app

Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker can then carry out fraudulent transactions in the new profile, potentially separating them from signs of malware detected elsewhere on the device.

To do this, Gigabud installs Vwork, a malicious version of the legitimate open-source tool Shelter. Shelter normally lets Android users isolate apps or run second copies of them in a work profile. Vwork modifies those functions so that Gigabud can control them remotely. The aim is to clone a target banking app into the new work profile, then let the operator commit fraud there.

Group-IB says this can break the connection between malware detected in the personal profile and a risky transaction originating from the work profile, potentially weakening bank-side anti-fraud or in-app malware-detection systems that do not correlate activity across Android profiles. Android work profiles are normally used to keep work apps and data separate from personal ones.

Because apps in different profiles are isolated from each other, a banking app or security tool may not connect malware detected in the personal profile with something taking place in a cloned app in the work profile. How an attack works Victims are lured into sideloading a fake airline, tax, or government app through phishing sites, messages, or social media.

To take over the device, Gigabud asks for Accessibility access, overlay permission to display over other apps, and an exemption from battery-optimization. These permissions enable remote interaction and credential-theft techniques such as overlays.

Read more →