Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection

Published September 9, 2026

Attackers trick Android users into installing fake banking apps that secretly copy real apps into a hidden work profile. This lets them steal money without triggering fraud alerts on the main phone.

Report priority
Medium
Targets
Android

How it works

  • Attackers send fake airline, tax, or government apps via phishing links, messages, or social media.
  • These apps install Gigabud malware, which then copies real banking apps into a hidden Android work profile.
  • The fake banking app in the work profile lets attackers bypass fraud checks on the main phone, making theft harder to spot.

What to do

Check if you installed any fake airline, tax, or government apps recently. Look for unusual banking apps in your work profile. If you see a fake banking app that isn't from your real bank, uninstall any suspicious apps immediately. Also, check if you've lost money unexpectedly from your bank account.

Reset your banking app passwords and enable two-factor authentication. Contact your bank to report the fraud and freeze your accounts if needed. For affected users, Group-IB recommends checking for Gigabud malware using security tools like Malwarebytes or Bitdefender.

Technical details

A user in Indonesia clicks a phishing link for a fake tax app. The app secretly installs Gigabud malware and copies a real banking app into a hidden work profile. The attacker then uses the fake banking app in the work profile to steal money without triggering fraud alerts on the main phone.

A new Android banking fraud campaign uses Gigabud, an RAT (remote-access trojan) first seen in 2022, to bypass fraud detection by cloning legitimate banking apps into a hidden Android Work Profile. The attack begins with victims sideloading fake apps, disguised as airline, tax, or government tools, via phishing or social media. Once Gigabud gains Accessibility, overlay, and battery exemption permissions, it remotely installs Vwork, a modified version of the open-source Shelter app cloner, creating an isolated work profile.

The cloned banking app runs undetected within this profile, allowing attackers to execute transactions while hiding malicious activity in the personal profile. Between February and July 2026, Group-IB observed 1,469 compromised devices and 1,281 potential login attempts in Indonesia, with estimated losses of $960,939. The technique exploits Android's profile isolation to evade fraud alerts, as security signals from the personal profile don't carry over into the cloned app's environment.

The campaign targets users in Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and a GCC member state, linked to the GoldFactory threat group.