Malware
Gigabud
Gigabud is the name of an Android Remote Access Trojan (RAT) Android that can record the victim's screen and steal banking credentials by abusing the Accessibility Service. Gigabud masquerades as banking, shopping, and other applications. Threat actors have been observed using deceptive websites to distribute Gigabud RAT.
Indicators of Compromise 4
MITRE ATT&CK TTPs 3
Source Articles
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan, attributed to the threat actor GoldFactory, has evolved to use a second malicious app called Vwork to create Android work profiles. This technique isolates a tampered banking app within the work profile, evading malware detection by legitimate banking apps running in the personal profile. The attacker gains full control via Accessibility services, overlays fake login screens, and steals credentials and transaction data. This method has been confirmed in Indonesia, with activity observed across multiple countries, resulting in nearly $1 million in estimated losses.
hacker-news ·18h ago
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Threat actors are abusing Google Play's Early Access program to distribute deceptive Android apps that promise rewards, casino winnings, or premium content but fail to deliver. These apps bypass user reviews and ratings, enabling malicious actors to promote them via social media ads featuring AI-generated celebrity deepfakes. The apps often deliver virtual rewards initially but stall progression before withdrawals, serving excessive ads to generate illicit revenue. Additional Android malware families such as Hagaseca, Mantax Otax, StreamRat, and Vwork are also active, with capabilities ranging from remote access and data theft to ransomware and financial fraud.
hacker-news ·14h ago