Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Android banking fraud is entering a deceptive phase. Attackers are using malware that copies targeted banking apps into a concealed Android work profile, separating a fraudulent session from warning signs seen on the phone.
The operation begins with Gigabud, an Android remote-access trojan active since 2022. Victims are lured through phishing sites, messaging apps, or social-media posts into sideloading fake airline, tax, or government applications, while fake banking app downloads can turn a brand into a trap.
Group-IB analysts identified Vwork, a modified version of the open-source Shelter app cloner, appearing minutes after Gigabud infections alongside tampered banking applications.
The researchers link the activity to GoldFactory and found compatible samples targeting Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and a Gulf Cooperation Council member state.
Group-IB said in a report shared with Cyber Security News (CSN) that from February through July 2026, researchers observed about 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated losses of roughly $960,939.
Those figures reflect observed activity rather than the full scope, but show why Android banking trojan campaigns remain a concern.
Hackers Clone Banking Apps Into Hidden Android Work Profiles
Gigabud first asks for Accessibility access, permission to draw over other apps, and battery-saving exemption. If a victim agrees, operators can remotely control the device, list installed apps, place fake login screens over real banking apps, and capture the device lock-screen code.
The next stage is simple but effective. The operator installs Vwork, which creates an isolated work profile and clones a banking app into it. In a confirmed Indonesian case, the cloned app was a fake version of a bank application.
.webp)
Android keeps applications in separate profiles isolated. That boundary is intended to protect work and personal data, but attackers use it to make the banking session look new.
A security signal tied to malware in the personal profile may not follow the cloned application into the work profile. The operator can then conduct transactions through the clean-looking profile while hiding activity behind a black screen.
The bank may see a new environment rather than the already-flagged personal profile, weakening the connection between device risk and a fraudulent transfer. Similar hidden remote-control Android attacks demonstrate how control features can be concealed from victims.
Vwork reduces visible clues. Its launcher icon is hidden and cloning functions can be controlled by another app. Gigabud includes commands to initialize Vwork, clone an application, and upload the clone list, showing the tools were designed to work together.
Phishing Delivery and Defensive Signals
An early warning is a consumer phone unexpectedly creating an isolated work profile. A banking app installed across profiles, a nearly empty profile, or a second suspicious installation shortly afterward should raise risk.
For users, the advice is simple: install applications only from official stores, reject Accessibility requests from apps that are not genuine accessibility tools, and use a banking second factor that does not depend on SMS. A raw app file sent through a chat is not a legitimate bank distribution channel.
Banks and wallet providers should bind logins to trusted devices, examine unusual session actions, and block high-risk transactions when an unrecognized app has active Accessibility access. Detection should combine signatures with behavior, rather than assuming one malware alert is enough.
This case underlines a broader shift in mobile fraud. Attackers combine social engineering, overlays, remote access, and Android features meant for legitimate separation. banking PIN theft malware shows how overlays and device control can scale financial theft.
The key lesson is that a clean-looking banking session is not always a clean device. Security teams should treat unexpected work-profile creation, cross-profile application duplication, and accessibility abuse as linked warning signs.
That approach can expose the fraud path before a transfer is completed. It also helps teams distinguish ordinary work use from coordinated account takeover before funds leave an account during urgent financial fraud investigations.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 | Gigabud sample |
| SHA-256 | ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae | Gigabud sample |
| SHA-256 | 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc | Gigabud sample |
| SHA-256 | 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf | Gigabud sample |
| SHA-256 | 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 | Gigabud sample |
| SHA-256 | 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c | Gigabud sample |
| SHA-256 | 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 | Vwork sample |
| SHA-256 | 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb | Modified banking application sample |
| SHA-256 | 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc | Modified banking application sample |
| Android package | net.yy.vwork | Vwork package identifier referenced by Gigabud samples |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
The post Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection appeared first on Cyber Security News.

.webp)

.webp)

.webp)
.webp)
.webp)















.webp)

.webp)
