The Gigabud trojan has adopted a new strategy to bypass security measures in banking apps on Android devices. According to a report by Group-IB, the malware installs an additional app that sets up a work profile on infected smartphones, allowing it to conceal its activities from the banking app’s malware detection systems.
How Work Profiles Shield Malware
Work profiles on Android create a partitioned space typically used by businesses to segregate work-related apps from personal ones. This separation helps the trojan remain undetected by the banking app’s malware scanners, as these scanners generally only check the personal space. Group-IB confirmed the presence of this tactic on devices in Indonesia, where the full infection chain was observed.
Documentation from Android indicates that any app in the main profile can initiate a work profile setup, with users being notified about the process. This feature is exploited by the trojan to create a concealed environment for its fraudulent activities.
The Mechanics of Gigabud and Vwork
Gigabud, a remote access trojan active since 2022, is linked to a group known as GoldFactory. It masquerades as legitimate apps like those from national airlines or government portals to infiltrate devices. Once installed, it seeks Accessibility permissions, enabling it to control the device remotely.
This trojan uses an app called Vwork to manage work profiles. Vwork functions similarly to Shelter, an open-source tool for duplicating or isolating apps within work profiles. However, Vwork automates the process, allowing the trojan to manipulate the work profile without user intervention.
Impact and Prevention
The report highlights that the malware has been particularly active in Indonesia, with a significant number of devices compromised. Group-IB estimates losses of approximately $960,000 due to this campaign, although these figures are based on their observations and may not represent the total impact.
To mitigate risks, users are advised to install apps only from official stores and deny Accessibility permissions to non-essential apps. For banks, indicators of compromise include unexpected work profiles, duplicate banking apps, and unnecessary Accessibility permissions.
Group-IB’s research underscores the evolving tactics of cybercriminals, emphasizing the need for vigilant security practices both for users and financial institutions. As the landscape of mobile threats continues to change, awareness and proactive measures remain crucial.
