The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.
A work profile is a separate space that Android typically reserves for employer apps, and what’s inside it is kept separate from everything in the personal space. That split hides the trojan from the banking app’s own malware checks, Group-IB said, so a fraudulent payment can look unrelated to the alert already raised on the phone. It has confirmed the full chain on infected devices in Indonesia.
Android’s platform documentation says any app in the phone’s main profile can start the setup for a work profile, and that the user is told what a work profile does before one is created.
Group-IB said banking apps carry security code that looks for known malware on the phone. From inside a work profile, that scan does not reach the personal space where the trojan sits.
Gigabud is a remote access trojan, malware that hands its operator live control of the phone. It has been active since 2022 and links it to a group it calls GoldFactory, which reaches phones as a fake app posing as a national airline, a tax office, or a government portal, installed from outside the official store.
On first launch, it asks for Accessibility access, permission to draw over other apps, and permission to keep running in the background to save battery. Giving it Accessibility access is the point where the operator gains real control of the device.
It then sends the operator a list of every app on the phone so that banking targets can be identified. When the victim opens their real banking app, a fake login screen appears on top and captures their keystrokes. A second overlay, invisible to the user, takes the phone’s lock screen code.
Group-IB said the operator can run transactions on the victim’s phone by tapping and typing through Accessibility, while a black screen covers what is happening.
That second app is called Vwork. Group-IB said its architecture and class names match Shelter, an open-source tool that uses the same work profile feature to let a phone’s owner isolate or duplicate apps.
The difference is who is in control. Shelter is worked by hand, by the person holding the phone. Vwork opens the same jobs to other apps: set up a work profile, clone an app into it, list what is in there, and open an app inside.
Group-IB said the checks that stopped other apps from calling those functions have been taken out, so any app on the device can drive Vwork. Before it clones anything, Vwork asks an external server for permission, and Gigabud carries commands written specifically for it.
Shelter walks a user through several screens before creating a profile. Vwork cuts that down to a single prompt, written in Chinese, Group-IB said.
On devices in Indonesia, Group-IB said, the installs arrived in order: Gigabud first, Vwork within minutes, then the tampered banking app.
In the one case the report describes in detail, what went into the profile was not a duplicate of the victim’s own banking app. Group-IB said, “the copy was a fake version of a real Indonesian bank’s app.”
Group-IB analyzed a single Vwork sample and described it as still under active development. Some of the added functions are unstable and do not behave as intended on Android builds close to the open-source version. The report does not say which phones or Android versions the technique does work on.
Gigabud samples built to work with Vwork have been found aimed at Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Türkiye, and one Gulf Cooperation Council country that Group-IB did not name. Those are samples, not confirmed infections. Only the Indonesian chain has been confirmed.
Between February and July 2026, Group-IB counted about 1,469 compromised devices and 1,281 possibly compromised logins in Indonesia, with estimated losses of about $960,000. The counts cover what Group-IB itself observed rather than the country as a whole, and it said they show observed activity and should not be read as the full picture. It did not say how many of those devices had Vwork on them.
Group-IB links both tools to GoldFactory. It pointed to a branch of Vwork’s code that references Gigabud package names, network indicators the two share, and developer logs written in Chinese, and said it cannot publish those indicators.
Checking a Phone for a Work Profile
The work profile itself shows up in the phone’s settings. Google’s guidance for Android users outlines where to find it and how to delete it.
- Open Settings, then Passwords and accounts. A Work tab appears there if the phone has a work profile.
- Apps within a work profile display a small briefcase badge on their icons.
- To delete it, open the Work tab, choose Remove Work Profile, then Delete. Google says this removes everything stored inside the profile.
- Check that the app that set the profile up is gone. Group-IB said Vwork keeps its icon out of the app launcher, though it still shows up in a file manager.
Google’s steps assume the phone belongs to the person using it, because the user cannot remove a profile an employer owns. Group-IB’s report does not say whether deleting the profile ends the risk while Gigabud is still installed in the personal space.
Group-IB’s advice to users is to install apps only from official stores, to refuse Accessibility access to any app that is not an accessibility tool, and to use a second factor for banking apps that does not rely on SMS.
For banks, the signs it lists are things the phone does rather than known malware files: a work profile appearing on an ordinary consumer phone that nobody set up, the same banking app showing install markers in both profiles, a profile holding none of the apps a person would normally have, and Accessibility switched on for an app with no reason to need it.
Vwork was found during earlier Group-IB research into GoldFactory’s campaign of tampered banking apps in Southeast Asia, published in December 2025. Group-IB said Vwork has been seen in the wild only in that campaign.
Putting a banking app inside a container to get around its defenses is not new. Promon described FjordPhantom in 2023, which ran a real banking app inside a virtual container so it could change how the app behaved from the inside. That worked by breaking the wall Android puts between apps. Vwork does close to the reverse, using a wall Android already provides to put the Trojan beyond the checks Group-IB described.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.



