Gigabud banking malware hides in Android work profiles
The Gigabud banking trojan now tricks Android phones into creating a fake work profile, then hides a fake banking app inside it to bypass security checks. This lets the attacker steal money without the real banking app noticing.
- Report priority
- Medium
- Targets
- Android
How it works
- The Gigabud malware first infects a phone through a fake app download.
- Once inside, it tricks the phone into creating a fake work profile, a separate space for employer apps.
- Then it drops a fake banking app inside that profile.
- When the real banking app checks for fraud, it only looks in the personal space and misses the fake app.
- The attacker can then steal money without the real app detecting it.
What to do
Check if you have any fake or unknown apps installed on your phone. If you see a work profile labeled with a company name you don't recognize, it could be created by Gigabud malware. Also, watch for unusual banking app behavior, like failed logins or unexpected transactions.
Uninstall any suspicious apps immediately. If you suspect Gigabud malware, reset your phone to factory settings and restore only trusted backups. Keep your phone's operating system and apps updated to reduce risks. If you notice unauthorized transactions, contact your bank right away.
Technical details
The Gigabud banking trojan now abuses Android's work profile feature to evade detection by banking apps. After infecting a device, it installs a secondary app that creates a hidden work profile and places a modified banking client inside it. Since work profiles are isolated from personal apps, security checks by legitimate banking software cannot detect the tampered version.
This allows Gigabud to bypass fraud detection while maintaining access to sensitive financial data. The technique was documented by Group-IB on September 9.