Home Β· Wiki Β· Incidents & Campaigns
type: incident Β· created: 2026-09-11 Β· updated: 2026-09-11 Β· tags: [incident, gigabud, goldfactory, android, banking-trojan, mobile-malware, vwork, banking] Β· confidence: high Β· severity: high Β· affected_sectors: [financial-services] Β· au_impact: false

Group-IB has documented a new capability in the Gigabud Android banking trojan, attributed to the GoldFactory group: a companion app called Vwork β€” a weaponised fork of the open-source app cloner Shelter β€” that creates an Android work profile on the infected device and installs a tampered banking app inside it. Because Android keeps work-profile content isolated from the personal profile, a banking app's own malware checks do not reach Gigabud where it sits, decoupling the fraud from the alert already raised on the same handset. The full chain has been confirmed on infected devices in Indonesia.

Attribute Detail
Malware Gigabud (Android RAT / banking trojan), active since 2022
Companion Vwork β€” weaponised fork of Shelter, packed with dpt-shell
Attribution GoldFactory
Confirmed chain Indonesia (Gigabud β†’ Vwork within minutes β†’ fake banking app)
Sample targeting Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, Philippines, Thailand, TΓΌrkiye, one GCC state
Reported Group-IB, 2026-09-09

On first launch Gigabud requests Accessibility access, draw-over-other-apps permission and background-run permission; Accessibility is the point at which the operator gains live remote control. It uploads a full app inventory so banking targets can be identified, overlays a fake login screen when the victim opens their real banking app, and invisibly captures the lock-screen code. Group-IB found that Vwork strips Shelter's restrictions on cross-profile interaction, exposes its cloning functions as an interface any app on the device can call, hides its launcher icon, and reduces the multi-screen work-profile provisioning flow to a single Chinese-language prompt. In the case described in detail, the app placed inside the work profile was not a copy of the victim's own banking app but a fake version of a real Indonesian bank's app. The technique maps to Group-IB's Fraud Matrix entries T2097.001 (mobile application cloning) and T2188.002 (automation via mobile app).