hacker-news · Crawled Sep 10, 2026

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

3 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

The Gigabud banking trojan, attributed to the threat actor GoldFactory, has evolved to use a second malicious app called Vwork to create Android work profiles. This technique isolates a tampered banking app within the work profile, evading malware detection by legitimate banking apps running in the personal profile. The attacker gains full control via Accessibility services, overlays fake login screens, and steals credentials and transaction data. This method has been confirmed in Indonesia, with activity observed across multiple countries, resulting in nearly $1 million in estimated losses.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 3 extracted

Type Value Detail
Filename Vwork Details →
GitHub Repo Shelter Details →
GitHub User Shelter Details →

MITRE ATT&CK TTPs 3 techniques