Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Trojan Uses Work Profiles to Evade Banking App Security

Trojan Uses Work Profiles to Evade Banking App Security

Posted on September 10, 2026 By CWS

The Gigabud trojan has adopted a new strategy to bypass security measures in banking apps on Android devices. According to a report by Group-IB, the malware installs an additional app that sets up a work profile on infected smartphones, allowing it to conceal its activities from the banking app’s malware detection systems.

How Work Profiles Shield Malware

Work profiles on Android create a partitioned space typically used by businesses to segregate work-related apps from personal ones. This separation helps the trojan remain undetected by the banking app’s malware scanners, as these scanners generally only check the personal space. Group-IB confirmed the presence of this tactic on devices in Indonesia, where the full infection chain was observed.

Documentation from Android indicates that any app in the main profile can initiate a work profile setup, with users being notified about the process. This feature is exploited by the trojan to create a concealed environment for its fraudulent activities.

The Mechanics of Gigabud and Vwork

Gigabud, a remote access trojan active since 2022, is linked to a group known as GoldFactory. It masquerades as legitimate apps like those from national airlines or government portals to infiltrate devices. Once installed, it seeks Accessibility permissions, enabling it to control the device remotely.

This trojan uses an app called Vwork to manage work profiles. Vwork functions similarly to Shelter, an open-source tool for duplicating or isolating apps within work profiles. However, Vwork automates the process, allowing the trojan to manipulate the work profile without user intervention.

Impact and Prevention

The report highlights that the malware has been particularly active in Indonesia, with a significant number of devices compromised. Group-IB estimates losses of approximately $960,000 due to this campaign, although these figures are based on their observations and may not represent the total impact.

To mitigate risks, users are advised to install apps only from official stores and deny Accessibility permissions to non-essential apps. For banks, indicators of compromise include unexpected work profiles, duplicate banking apps, and unnecessary Accessibility permissions.

Group-IB’s research underscores the evolving tactics of cybercriminals, emphasizing the need for vigilant security practices both for users and financial institutions. As the landscape of mobile threats continues to change, awareness and proactive measures remain crucial.

The Hacker News Tags:Android malware, banking security, Cybersecurity, Gigabud, GoldFactory, Group-IB, mobile security, Trojan, Vwork, work profiles

Post navigation

Previous Post: Fake GTA 6 Downloads Spread Malware Campaign
Next Post: Inside Vinnie Liu’s Journey from NSA to Bishop Fox

Related Posts

84 Security Flaws Uncovered in 4G and 5G Networks 84 Security Flaws Uncovered in 4G and 5G Networks The Hacker News
Google Introduces Selfie Video for Account Access Recovery Google Introduces Selfie Video for Account Access Recovery The Hacker News
Chinese Hackers Exploit Linux Login Systems for Years Chinese Hackers Exploit Linux Login Systems for Years The Hacker News
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers The Hacker News
GopherWhisper Attacks Mongolian Government with Go Malware GopherWhisper Attacks Mongolian Government with Go Malware The Hacker News
Password Reuse in Disguise: An Often-Missed Risky Workaround Password Reuse in Disguise: An Often-Missed Risky Workaround The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic
  • China-Linked Hackers Exploit Sogou Flaw for Backdoor
  • Hackers Hide AI Threats in Plain English, Evade Security
  • Exploits Target JFrog Artifactory Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark