Gigabud Uses Android App Cloning to Evade Fraud Detection
Gigabud is a mobile malware that copies real banking apps into a separate workspace on Android phones. This lets it bypass fraud alerts by hiding its activity from the main app.
- Report priority
- Medium
- Targets
- Android
How it works
- Gigabud tricks Android users into installing a fake banking app that looks real.
- Once installed, it creates a hidden copy of the real banking app inside the phone's work profile, a separate workspace.
- When the user logs into the real app, Gigabud's fake version runs in the background, sending fraudulent transactions while the real app stays clean.
- This lets the malware avoid fraud detection because the alerts only check the real app, not the hidden copy.
What to do
Check if you have any banking apps installed that you did not download from the official Google Play Store. Look for apps with unusual names, icons, or permissions. If you see a banking app you don't recognize, uninstall it immediately. Also, check your transaction history for unauthorized activity.
Uninstall any suspicious banking apps right away. Enable Google Play Protect to scan for malicious apps. Keep your Android system updated to the latest version. If you suspect fraud, contact your bank immediately and report the incident.
Technical details
A victim downloads what looks like a legitimate banking app from a third-party site. After installing it, the malware clones the real banking app into the phone's work profile. When the victim logs into their real banking app, Gigabud's fake version processes unauthorized transactions, while the real app shows no suspicious activity.
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud