Vwork: Weaponized Open-source Software as an Addon for Gigabud

Published September 9, 2026

GoldFactory attackers use a fake version of the open-source app-cloning tool Shelter, called Vwork, to hide their banking malware Gigabud on Android phones. After tricking users into installing a fake app, the malware clones real banking apps inside a hidden work profile to steal money without detection.

Report priority
High
Targets
Threat actor: GoldFactory+2 more

How it works

  • GoldFactory attackers send fake Android apps disguised as real banking services.
  • When users install them, the apps secretly install Gigabud malware.
  • Gigabud then uses a modified version of Shelter, called Vwork, to create a hidden work profile on the phone.
  • Inside that profile, Gigabud clones real banking apps to steal credentials and perform fraudulent transactions.
  • The cloned apps look real to users but secretly send stolen login details and money to the attackers.

What to do

If you live in Brazil, Colombia, Egypt, or another country listed above and recently installed an unknown banking app on your Android phone, check for suspicious work profiles. Look for a hidden profile named 'Work' or similar in your phone's settings under 'Profiles & devices.' If you find one, uninstall it immediately and scan your phone with a trusted antivirus app.

If you suspect your phone is infected, uninstall any unknown banking apps right away. Then, check your bank accounts for unauthorized transactions and report them to your bank. For a full cleanup, use a trusted antivirus tool like Malwarebytes or Bitdefender to remove the malware. If you see signs of fraud, contact your bank's fraud department immediately.

Technical details

Affected software: Threat actor: GoldFactory, Finance, Targets: Brazil, Colombia, Egypt

In Indonesia alone, between February and July 2026, over 1,400 phones were infected with Gigabud. The attackers stole login details from 1,281 banking apps and made off with about $960,939 in fraudulent transactions.

Gigabud is an Android remote access trojan (RAT) first observed in 2022, linked to the GoldFactory threat group. It now abuses Vwork, a weaponized fork of the open-source app-cloning tool Shelter, to bypass security defenses. After infecting a device, Gigabud installs Vwork to create isolated work profiles and clone legitimate banking apps within them, evading signature-based detection in mobile security SDKs.

The attack chain begins with phishing lures delivering fake apps, followed by credential theft via overlay attacks and fraudulent transactions executed in the cloned banking apps. Between February and July 2026, researchers observed 1,469 compromised devices and 1,281 potential login compromises in Indonesia alone, with estimated financial losses of approximately $960,939.