Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

Gigabud’s New Trick Hides Cloned Banking Apps From Fraud Detection

What Happened

Group-IB researchers published findings on September 9 describing a new evasion technique used by the Gigabud Android banking trojan, tied to the threat group GoldFactory. Once Gigabud infects a device and gains accessibility permissions, it installs a second app called Vwork, a modified version of an open-source Android cloning tool. Vwork creates a separate Android Work Profile on the device and clones the victim’s legitimate banking app into it. Because banking apps scan for malware indicators in the main personal profile, a fraudulent transaction launched from inside the cloned app in the work profile does not trigger the security check already tied to the phone. Group-IB tracked Vwork-compatible Gigabud samples across eleven countries including Brazil, Mexico, the Philippines, and Turkey, with about 1,469 compromised devices and an estimated $960,000 in losses in Indonesia between February and July 2026. Read the full research via The Hacker News.

Why This Matters for Canadian Organizations

No confirmed Gigabud or Vwork activity has surfaced in Canada yet, but the technique itself is the real story. Android’s Work Profile feature exists for legitimate enterprise device management, and turning it into a blind spot for fraud detection defeats a control Canadian banks and fintechs rely on across their entire mobile user base. Techniques built for one region routinely appear in North America once affiliate networks pick them up and resell the toolkit. Canadian financial institutions running mobile fraud detection built around device and app inventory checks should treat this as an early warning rather than a foreign problem.

What to Do

Ask your mobile banking security vendor whether fraud detection scans reach across all Android Work Profiles on a device, not only the primary profile. Add detection rules for unexpected Work Profile creation events on enrolled devices, and monitor for sideloaded cloning utilities like Vwork alongside standard banking trojan indicators. Update customer-facing guidance to warn against installing apps from outside Google Play, since this channel remains the entry point for Gigabud infections.

Enjoy this article? Don’t forget to share.