The record
Written from the 1 report below. Nothing here is unsourced.
- The Gigabud banking trojan installs a second app called Vwork that creates an Android work profile to hide from security checks, according to security firm Group-IB.
- The trojan hides in the phone's personal space, so a banking app's malware scan inside the work profile finds nothing, letting a fraudulent payment go through.
- Gigabud is a remote access trojan linked by Group-IB to a group called GoldFactory, which distributes it as fake apps outside official stores since 2022.
- The technique has been confirmed on infected devices in Indonesia, with Group-IB counting about 1,469 compromised devices and estimated losses of about $960,000 between February and July 2026.
- The finding matters because the trojan is under active development and samples targeting Brazil, Mexico, Thailand, the Philippines and other countries have already been found.
What to watch next
- Whether the technique spreads beyond Indonesia, since samples built for Vwork have been found targeting more than ten countries but only the Indonesian chain is confirmed.
- Whether deleting the work profile actually ends the risk while Gigabud remains installed in the personal space, which the report does not answer.
- Which Android phones and versions the technique works on, since the report says Vwork is still unstable on some builds and does not state what it works on.
Coverage1
1 report
English national1
All filed from India
Named Indonesia · Brazil · Colombia · Egypt · Thailand · Philippines · Türkiye · Morocco · Mexico · Laos · Google · Shelter · Gigabud · GoldFactory · Group-IB · Vwork
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
