Select a theme from the list.
Insights

From our experts

Latest
Gigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session Hijacking
Security Insight

Gigabud Hides Banking Fraud Inside Android Work Profiles

Gigabud Hides Banking Fraud Inside Android Work Profiles
Photo by Miguel Á. Padriñán on Pexels

The Gigabud banking trojan has adopted a second malicious application that creates an Android work profile and installs a tampered banking app inside the isolated space. The technique can prevent a banking application's security checks from seeing malware operating in the phone's personal profile.

The operators of the Gigabud banking trojan are abusing Android work profiles to create a hidden environment for fraudulent transactions. The technique uses a second application, known as Vwork, to establish a work profile and place a manipulated banking application inside it.

Work profiles are legitimate Android features commonly used to separate corporate applications and information from a person's private apps. That isolation becomes dangerous when controlled by malware. A banking application running inside the work profile may be unable to detect Gigabud operating in the personal profile, weakening security checks that normally search the device for malicious software.

A Multi-Stage Mobile Attack

Gigabud is distributed through applications impersonating airlines, government agencies, tax services and other trusted organizations. After installation, it requests powerful permissions, including Android Accessibility access, the ability to display content over other applications and permission to continue operating in the background.

Those capabilities let the malware inspect installed applications, place fake login screens over legitimate banking software and remotely control taps and keyboard input. Operators can reportedly conceal their actions behind a black screen while conducting transactions on the infected phone.

Vwork then creates the separate work environment. Its code appears to be derived from Shelter, a legitimate open-source application for isolating or duplicating Android apps. Security checks that normally limit which applications can control Shelter-like functions were reportedly removed, allowing Gigabud to direct the profile creation and launch applications within it.

Confirmed Activity and Wider Targeting

The complete chain has been confirmed on devices in Indonesia. Samples supporting the Vwork technique have also been associated with targeting in Brazil, Colombia, Egypt, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye and other markets, although samples alone do not prove successful infections.

Researchers observed roughly 1,469 compromised devices and 1,281 potentially compromised account logins in Indonesia between February and July 2026, with estimated losses approaching $960,000. Those figures represent only the activity visible to the researchers.

What Users and Banks Should Do

  • Avoid installing applications from links, messages or unofficial stores.
  • Treat unexpected Accessibility permission requests as a serious warning.
  • Check Android account settings for an unfamiliar Work tab.
  • Look for briefcase badges on applications that should not be managed.
  • Contact the bank from a separate device if unauthorized profile activity is discovered.

I believe mobile security teams must now treat Android profile boundaries as part of the attack surface. Isolation protects privacy only when the device owner or a trusted employer controls it. When malware becomes the profile administrator, the same boundary can divide security telemetry and help criminals hide fraudulent activity.

Talk to our team →

Latest

Gigabud Hides Banking Fraud Inside Android Work ProfilesSep 11, 2026Surfshark Test Server Breach Exposes the Security Gap Between Development and ProductionSep 11, 2026AI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzSep 11, 2026Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path