GoldFactory Weaponizes Open-Source Vwork App Cloner in Gigabud Banking Malware Attacks
GoldFactory's Gigabud banking malware now uses a modified version of the open-source Vwork app to sneak onto Android phones. Attackers trick users into installing this fake app, which then steals banking details and money.
- Report priority
- Medium
How it works
- Attackers modify the open-source Vwork app to include Gigabud malware.
- When users download this fake Vwork app from untrusted sources, the malware steals banking credentials and sends money to attacker-controlled accounts.
- The fake app mimics legitimate banking theft tools but uses a repurposed app to avoid detection.
What to do
If you installed the fake Vwork app from sources other than the official Google Play Store, check your installed apps for any suspicious or unfamiliar Vwork app. If you see an unknown Vwork app, uninstall it immediately and scan your phone for malware using a trusted antivirus app.
Uninstall any suspicious Vwork app right away. Use Google Play's official app store for all downloads. Run a full malware scan on your phone using a trusted security app like Malwarebytes or Bitdefender. If you suspect your banking details were stolen, contact your bank immediately and monitor your accounts for unauthorized transactions.
Technical details
Attackers create fake Vwork app downloads on third-party app stores or via phishing links. When a user installs the fake app, Gigabud malware activates, intercepting banking logins and transferring funds without the user's knowledge.
GoldFactory has expanded the evasion capabilities of its Gigabud Android banking trojan by deploying Vwork, a weaponized fork of the open-source Shelter application.