Hackers Clone Banking Apps into Hidden Profiles, Android Malware Raises New Fraud Concerns

Rinky Rai
By Rinky Rai - A freelance journalist
3 Min Read

Cybercriminals are deploying advanced Android malware that clones targeted banking applications inside hidden Work Profiles, allowing attackers to conduct unauthorized transactions while bypassing standard fraud detection systems. Security researchers have traced the operation to Gigabud, a Remote Access Trojan active since at least 2022, paired with Vwork, an application cloning utility based on the open-source software Shelter. The campaign tricks victims through phishing links on social media and messaging channels into installing malicious files disguised as government, tax, or airline utilities, as well as fake financial services.

Exploiting Android Work Profiles to Evade Security Checks

​Once granted device privileges, Gigabud seeks Accessibility permissions, overlay capabilities, and exemptions from battery optimizations to capture screen credentials and remotely control the smartphone. The attack proceeds by deploying Vwork to establish an isolated Android Work Profile, inside which it duplicates the target banking application. Because the operating system treats personal and enterprise workspaces as distinct environments, security signals triggered by malware in the personal space do not automatically transfer to the isolated setup. This division provides attackers with an environment that appears clean to security mechanisms during fraudulent transactions.

​Investigators confirmed instances where fake financial applications functioned from inside these isolated work environments, including documented activity in Indonesia. Vwork was also observed concealing its launcher icon while accepting remote instructions from Gigabud to initiate setup, duplicate apps, and transmit inventory logs back to control servers.

Significant Financial Losses Recorded Across Global Targets

​Monitoring between February and July 2026 uncovered roughly 1,469 compromised devices and 1,281 compromised account credentials in Indonesia alone, resulting in estimated losses of 8.2 crore rupees. Analysts note that these numbers reflect only visible telemetry and point to a much broader international campaign linked to GoldFactory. Compatible malware samples have been detected targeting users across Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Turkiye, and a member country of the Gulf Cooperation Council.

​The findings demonstrate a coordinated strategy where cybercrime syndicates abuse legitimate device management features originally designed to separate professional and private phone usage.

Behavioral Safeguards Urged as Threat Tactics Evolve

​Security professionals warn that unexplained Work Profile installations, duplicated banking apps, and irregular Accessibility requests serve as clear indicators of a compromised smartphone. Users are advised to avoid sideloading APK files received over private messages and to limit sensitive permissions exclusively to verified programs obtained from official digital storefronts.

​A researcher at Algoritha Security noted that detecting standalone malicious files is no longer sufficient to stop modern banking fraud. Financial institutions and payment networks must shift focus toward behavioral analysis, correlating recent profile creation, overlay activity, and unusual transaction parameters to intercept unauthorized fund transfers before processing is completed.

Stay Connected