Android work profiles become a hiding place for Gigabud trojan

Group-IB found the long-running banking trojan building a second app that shelters inside Android's employer workspace.

CSBadmin
2 Min Read

A banking trojan has started using a part of Android built for employers to slip past the security checks that live inside banking apps.

Group-IB published its findings on September 9 and confirmed the whole chain on infected handsets in Indonesia. Gigabud itself has been around since 2022.

The new piece is a second app. Once installed it builds a work profile, the sandboxed area Android usually keeps for employer tools, then plants a doctored banking app inside it. Work profile contents stay walled off from the personal side, so the genuine app’s own scan cannot see the trojan next door.

The split delivers the cover. When the bank raises an alarm, a fraudulent transfer launched from the work profile appears to have nothing to do with it.

Control is the whole point. An operator with Gigabud on a phone effectively holds that phone, and Group-IB attributes the operation to a crew it names GoldFactory. That outfit spreads fake apps dressed up as a national airline, a tax office, or a government portal, sideloaded outside official stores.

Accessibility permission is the gate. On first launch the app requests it, along with permission to draw over other apps and a battery exemption. Granted that, the operator receives a list of installed apps, then floats a fake login screen above the real bank app to harvest keystrokes. A second invisible overlay lifts the lock screen code while a black screen conceals the taps.

Consumers should sidestep all of it by installing banking apps only from official stores and auditing which apps hold Accessibility permission.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.