Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Gigabud banking trojan uses app cloning to evade fraud detection

The Gigabud Android banking trojan now uses the Vwork app to clone legitimate banking applications into an isolated Android work profile, evading fraud detection by separating malicious activity from the user's personal profile. It steals credentials via fake login screens and captures one-time passcodes with overlays. Group-IB advises banks to monitor for unusual work profile creation and mismatched app markers across profiles, and to encourage users to download apps only from official stores.
Read Full Article →

Malware Gigabud banking trojan uses app cloning to evade fraud detection September 9, 2026 Share By SC Staff (Adobe Stock) As reported by Infosecurity Magazine, the Gigabud Android banking trojan has been updated with a new capability to clone banking applications into a separate Android work profile, creating a significant challenge for fraud detection systems. Researchers at Group-IB have identified that Gigabud is now being paired with Vwork, a modified version of the Shelter app, attributed to the GoldFactory threat group. This combination allows Gigabud to clone legitimate banking apps into an isolated work profile on an Android device. This technique circumvents security measures because malware alerts generated in the user's personal profile are not visible in the newly created work profile. Fraudsters can then conduct transactions from this isolated environment, making the activity appear to originate from a device with no prior malware history. Fake login screens are used to steal credentials, and overlays capture one-time passcodes. The full infection chain has been confirmed in Indonesia, targeting 11 countries including Brazil, Colombia, and Mexico. Group-IB observed significant losses in Indonesia, with approximately $960,939 estimated between February and July 2026. Gigabud typically spreads through phishing sites and social media, masquerading as legitimate applications. To combat this, Group-IB advises banks to monitor for unusual work profile creation, matching banking app markers across profiles, and excessive accessibility permissions. They also recommend device binding and encouraging users to download apps only from official stores. Source: Infosecurity Magazine SC Staff Related Network Security F5 BIG-IP malware hides web shells in memory to evade detection Steve Zurier September 9, 2026 Memory-resident malware targeting F5 BIG-IP appliances can evade file-based security defenses. Malware New Android RAT uses worm to target exposed ADB services SC Staff September 8, 2026 The RAT employs a concealed loader and a worm that actively scans for exposed Android Debug Bridge (ADB) services to install itself on vulnerable devices. Malware New browser malware uses remote commands to control Windows systems SC Staff September 3, 2026 The malware, disguised as a "privacy browser," was distributed via a deceptive sponsored search result after an employee mistyped a URL. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article