Between February and July 2026, Group-IB counted about 1,469 compromised devices and 1,281 possibly compromised logins in Indonesia, with estimated losses of about $960,000, the company reported on September 9.
How Gigabud uses Android work profiles to evade banking app checks
Group-IB's analysis shows the Gigabud remote access trojan now installs a second app, called Vwork, which creates an Android work profile and places a tampered banking app inside that separate space. Android keeps work-profile contents distinct from the phone's personal profile; Group-IB says that split prevents a banking app's internal malware checks — which look for known malware on the device — from seeing Gigabud in the personal space. That separation can let a fraudulent payment appear unrelated to any alert already raised on the phone.
What Gigabud and Vwork do on an infected phone
Gigabud arrives as a fake app — posing as a national airline, a tax office, or a government portal — installed from outside the official app store, Group-IB said. On first launch it requests Accessibility access, permission to draw over other apps, and permission to keep running in the background; Group-IB notes that granting Accessibility access is the point at which an operator gains live control of the device. From there Gigabud sends the operator a list of every app on the phone so banking targets can be identified. When a victim opens their genuine banking app, an overlay presents a fake login screen and captures keystrokes; a second, invisible overlay grabs the phone's lock-screen code. The operator can then perform transactions by driving taps and typing through Accessibility while a black screen conceals the activity.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleVwork's architecture, its ties to Shelter, and development status
Group-IB found Vwork's architecture and class names match Shelter, an open‑source tool designed to let a phone owner isolate or duplicate apps using Android work profiles. The difference, Group-IB emphasizes, is control: Shelter is manually operated by the device owner; Vwork exposes the same work‑profile functions to other apps. Group-IB said checks that previously prevented arbitrary apps from driving Shelter-like functions have been removed in Vwork, allowing any app on the device to operate it. Before cloning any app, Vwork queries an external server for permission, and Group-IB said Gigabud carries commands written specifically for Vwork. The company described the Vwork sample it analyzed as still under active development, with added functions that are unstable and that do not always behave as intended on Android builds close to the open-source version.
Confirmed infections, global samples, and attribution to GoldFactory
Group-IB confirmed the full infection chain on devices in Indonesia; it said other Gigabud samples built to work with Vwork were aimed at Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and one Gulf Cooperation Council country that Group-IB did not name, but noted those are samples rather than confirmed infections. In one detailed Indonesian case, Group-IB said "the copy was a fake version of a real Indonesian bank's app." Group-IB links both Gigabud and Vwork to a group it calls GoldFactory, pointing to a branch of Vwork's code that references Gigabud package names, shared network indicators, and developer logs written in Chinese, although the company said it cannot publish those indicators.
What this means for banks, end users, and technologists
- Banks and financial app teams: watch for behavioral signs rather than just file-based indicators — Group-IB lists indicators such as an unexpected work profile on a consumer phone, the same banking app showing install markers in both profiles, a profile holding none of the apps a person normally uses, and Accessibility enabled for an app with no legitimate reason to need it.
- End users: Group-IB's practical advice is to install apps only from official stores, refuse Accessibility access to any app that is not an accessibility tool, and use a second factor for banking that does not rely on SMS. Users can also check for a work profile via Settings → Passwords and accounts and remove it by choosing Remove Work Profile → Delete; Google says this deletes everything stored inside the profile.
- Mobile-security technologists: note Vwork's technique of using Android's built-in work-profile separation to hide malicious components; code-level ties to Shelter and an external permission check means defenses should consider cross-profile behavior and the possibility that tools intended for user-managed isolation can be repurposed by malware.
Group-IB's findings place a familiar toolset — overlays, Accessibility abuse, and fake apps — inside a new packaging trick: using Android's sanctioned work-profile partition to put the trojan beyond a banking app's internal checks. The company confirmed the chain in Indonesia and supplied counts of observed compromises there, but it also left open operational questions: for example, Group-IB does not say whether deleting the work profile removes the operational risk if Gigabud remains in the phone's personal profile. Defenders and users now must reckon with a tactic that turns a platform feature designed for enterprise security into a hiding place for mobile fraud.




