VYPR
researchPublished Sep 9, 2026· 2 sources

Hackers Clone Banking Apps into Hidden Android Work Profiles to Evade Fraud Detection

New Android malware campaigns leverage Gigabud RAT and Vwork app cloner to hide fraudulent banking activities by cloning apps into concealed work profiles.

A sophisticated new Android malware campaign is using a deceptive tactic to bypass fraud detection systems: cloning legitimate banking applications into hidden, isolated work profiles. This technique, detailed by Group-IB researchers, leverages the Gigabud remote-access trojan (RAT) and a modified app cloner called Vwork to create a clandestine environment for fraudulent transactions.

The attack chain begins with Gigabud, which has been active since 2022. Victims are typically lured into downloading malicious applications disguised as legitimate software, such as airline, tax, or government apps, through phishing sites, messaging apps, or social media. Once Gigabud infects a device, it requests extensive permissions, including Accessibility access, the ability to draw over other apps, and battery optimization exemptions. With these permissions, attackers gain remote control over the device, can overlay fake login screens on top of real banking applications, and capture sensitive information like screen lock codes.

Following the Gigabud infection, the attackers deploy Vwork, a tool based on the open-source Shelter app cloner. Vwork's primary function is to create a separate Android work profile on the victim's device. This work profile is isolated from the user's main personal profile, a feature designed by Google to separate work and personal data. However, attackers exploit this isolation to their advantage.

Once the work profile is established, Vwork clones a targeted banking application into this isolated environment. The cloned app may appear identical to the legitimate one, but it operates entirely within the hidden profile. This separation is crucial for evading fraud detection. Security systems that monitor the primary profile for suspicious activity or malware might not detect the fraudulent session occurring within the separate work profile.

Researchers have linked this campaign to the GoldFactory threat group and observed its activity across numerous countries, including Brazil, Colombia, Egypt, Indonesia, Mexico, and Thailand. In Indonesia alone, between February and July 2026, Group-IB observed approximately 1,469 compromised devices and 1,281 potentially compromised logins, resulting in estimated losses of around $960,939. This highlights the significant financial impact of this evolving attack vector.

The effectiveness of this method lies in its ability to present a seemingly normal banking session to the user and potentially to some security systems. By conducting transactions within the isolated work profile, attackers can mask malicious activity, making it appear as if a new, uncompromised device is initiating the transfer. The cloned app's launcher icon is often hidden, and its cloning functions can be controlled remotely by Gigabud, further obscuring the malicious operation.

To combat this threat, users are advised to download applications only from official app stores, be wary of Accessibility permission requests from non-legitimate apps, and utilize multi-factor authentication methods that do not rely solely on SMS. Banks are encouraged to strengthen their detection capabilities by looking for unusual session actions, blocking high-risk transactions, and correlating device risk signals with user behavior, especially when unexpected work profiles are created or applications are duplicated across profiles.

This campaign represents a broader trend in mobile banking fraud, where attackers combine social engineering, remote access trojans, and legitimate Android features to create complex and evasive attack chains. The tactic underscores the need for layered security approaches that go beyond simple signature-based detection and consider behavioral anomalies and the exploitation of device features.

This latest report from Infosecurity Magazine details how the Gigabud Android malware specifically utilizes app cloning to bypass fraud detection systems. The technique involves creating a separate instance of legitimate banking applications within a work profile, effectively isolating the malicious activity from security alerts and making it harder to trace fraudulent transactions back to the malware.

Synthesized by Vypr AI