DevOps
Gigabud / Vwork: Account Takeover via Android Banking App Cloning in Work Profiles
Anoymask DEV Community
6 views
1. Basic Information
Original Title: Indonesia Hit by Android Banking App Cloning Campaign
Source: Dark Reading, Group-IB
Publication Date: 2026-09-11
Severity: High
Basis for Severity: Actual financial losses and numerous compromised devices have been confirmed, and the enterprise Work Profile feature is being abused to isolate and evade detection in consumer banking fraud.
Original Link: Indonesia Hit by Android Banking App Cloning Campaign
Related Sources: Group-IB: Vwork App Cloning in Gigabud/GoldFactory, MITRE ATT&CK: Device Administrator Permissions
Related Malware: Gigabud, Vwork
Related Threat Group: GoldFactory
Related Products: Android, Android Work Profile, mobile banking applications
2. Executive Summary
Gigabud obtains accessibility permissions, deploys Vwork, and clones banking apps inside an Android Work Profile. It leverages the separation from the personal profile to register the device with the bank, enabling remote control and unauthorized fund transfers behind a black screen.
3. Attack Flow
Flow 1: Banking App Cloning Using Vwork via Gigabud
The victim sideloads an APK disguised as an airline, tax, or government app.
Gigabud requests accessibility permissions, display over other apps, and ignore battery optimizations. It collects credentials through a fake banking login screen and screen lock codes through another mechanism.
C2 commands deploy Vwork and create an Android Work Profile.
Vwork clones the banking app into the Work Profile, and Gigabud relays operation commands. Group-IB's confirmed examples also include deploying modified versions disguised as legitimate banking apps.
The attacker registers the cloned app as a new device behind a black screen overlay and transfers funds without authorization.
4. Attacker Positioning and Execution Location
External attacker who induces the victim to sideload the APK and grant permissions.
Once permissions are obtained, the attacker remotely controls the device screen and apps, operating the banking apps within the Work Profile.
5. Visibility for Victims and Administrators
Victims
Requests to install fake brand apps, permission prompts for accessibility, display over other apps, and ignore battery optimizations.
Unexpected briefcase icon for the Work Profile, duplicated banking apps, and a black screen during operation.
Administrators
APKs from unofficial sources, net.yy.vwork, rapid Work Profile creation, and banking app cloning.
Linking of new profiles and new devices from the same physical device, along with unusual transfers.
6. Success and Failure Conditions
Success Conditions
The user sideloads the malicious APK and grants accessibility and other permissions.
The device allows the creation of a Work Profile and the cloning of banking apps.
The bank does not carry over personal profile risk signals to the authentication of the new profile.
Failure Conditions
Inference: Restricting APK installation from external sites and unauthorized app permissions via device policies can block the reported delivery vector.
Inference: On managed devices, restrict unauthorized accessibility usage and Work Profile creation based on MDM capabilities.
Inference: Linking new device registration and transfer risk assessments on the bank side, and requiring additional authentication when necessary, can curb misuse after app cloning.
7. What Happens Upon Success
Theft of mobile banking credentials and transaction authentication.
Remote control and unauthorized fund transfers that are hard for the user to notice.
Inference: The same technique may be repurposed for other banking and payment apps. The targets and scope of success depend on the app and bank controls.
8. Observable Logs
Email
Group-IB reports APK distribution via social engineering such as SMS. Review messages and URLs provided by users. May not appear in corporate email logs.
Proxy / SWG / DNS
Inference: Communications to fake airline, tax, and government domains, Gigabud C2, and APK download sources.
Endpoint / EDR
Inference: Deployment of net.yy.vwork, accessibility service registration, overlays, ignoring battery optimizations, Work Profile creation, and app cloning.
Identity / IdP
Inference: Check new device registrations, changes in authentication methods, and login origins in bank records. The mapping between physical devices and profiles depends on available identifiers and bank cooperation.
SaaS / Cloud
Inference: New device registration for mobile banking, adding recipients and making transfers inconsistent with user behavior.
Network
Inference: C2 where Gigabud relays Vwork commands, and continuous communication associated with remote screen control.
9. Attack Success Criteria
Below are the ranges confirmed by public information and the determination criteria used in internal investigations.
User Action Confirmed: Public Info: Gigabud distribution utilizes APK installation from external sites and permission grants. Group-IB has confirmed the infection vector on the device.
Initial Execution Confirmed: Public Info: The deployment of Vwork and banking apps following Gigabud, using Work Profiles, has been reported.
Information Theft or Session Compromise Confirmed: Public Info: Credential theft via fake login screens has been reported. The 1,281 cases represent potentially compromised logins and not confirmed unauthorized transfer counts.
Subsequent Compromise Confirmed: Public Info: Group-IB reported banking operations on victim devices and estimated losses. Individual cases require confirmed unauthorized transfers in bank transaction records, and APK deployment or profile creation alone does not constitute successful transfer.
10. Investigation Playbook
Triggers
Granting accessibility to an unknown APK, net.yy.vwork, unexpected Work Profile, or duplicated banking apps.
Initial Response
Preserve the APK acquisition path, package, signature, permissions, profile creation time, and bank login time.
Device / Server
Check Android package lists, accessibility services, device policy management apps, overlays, Work Profiles, and ignored battery optimizations.
Authentication / Cloud
Investigate bank-side device IDs, profiles, device bindings, login IPs, added recipients, and transfer history.
Subsequent Operations
Inference: Check for additional APKs, cloning of other banking and wallet apps, and access permissions/usage traces for SMS. Notification theft is not treated as a confirmed behavior in this material.
Containment
Isolate the device from the network, contact the bank to invalidate sessions, device bindings, and credentials.
Preserve evidence, and wipe/re-enroll corporate devices according to management procedures. Check other devices using the same account.
Determination Categories
Separate APK contact, permission grants, Work Profile creation, successful bank authentication, and unauthorized transfers.
11. Defense and Detection Ideas
Single Event
Inference: Work Profile creation on non-MDM managed devices, or detection of net.yy.vwork.
Inference: Simultaneous grant of accessibility and overlay permissions to an unknown app.
Time-Series Correlation
Inference: Correlate sideloading -> accessibility -> Vwork -> profile creation -> banking app cloning -> new device authentication -> transfer.
Hunting
Inference: Enumerate Work Profile creation sources, cloned high-value apps, and abnormal accessibility services across Android device fleets.
Log Gaps
When bank-side and device-side records cannot be correlated, it becomes difficult to confirm whether different profiles belong to the same physical device or to establish the link between registration and transfer.
Priority Countermeasures
Inference: Prioritize blocking sideloading, accessibility allowlists, Work Profile management, and integrating financial-side device bindings.
12. Facts / Inference / Hypothesis
Facts
Group-IB reported approximately 1,469 compromised devices, 1,281 potentially compromised logins, and an estimated $960,000 in losses observed in Indonesia between February and July 2026. These values reflect Group-IB's observation scope and do not represent the total regional damage scale.
Gigabud is distributed as fake airline, tax, and government apps outside official stores, and requests accessibility, display over other apps, and ignore battery optimizations.
Minutes after installation, Gigabud deploys Vwork (net.yy.vwork) and operates it using C2 commands such as initVwa, cloneApp, and uploadCloneApps.
Vwork is a modified version of the open-source tool Shelter, which clones target banking apps into a Work Profile. Vwork itself has no C2, and Gigabud relays its commands.
Attackers remotely operate the cloned apps behind a black screen overlay, appearing to the bank as a new device and new profile.
Inference
If infection, overlay, and accessibility signals from the personal profile are not shared with the banking app assessment in the Work Profile, traditional device-level rules may be bypassed.
Time-series detection spanning Work Profile creation, app cloning, device registration, and fund transfers is effective.
Hypothesis
No additional hypotheses. Unconfirmed items are listed in "Unanswered Questions and Further Investigation".
13. MITRE ATT&CK Mapping
T1660 Phishing (Confidence: high): Induces deployment using fake airline, tax, and government apps.
T1406.002 Obfuscated Files or Information: Software Packing (Confidence: medium): Group-IB reports that both Vwork and related Gigabud samples are packed with dpt-shell.
T1626.001 Abuse Elevation Control Mechanism: Device Administrator Permissions (Confidence: medium): Group-IB reports that Vwork and Gigabud request device administrator privileges. This is a separate behavior from the abuse of accessibility permissions.
T1453 Abuse Accessibility Features (Confidence: high): Uses accessibility as the foundation for screen operation, information retrieval, and remote control.
14. Unanswered Questions and Further Investigation
Target app lists and financial losses by country and bank.
Specific conditions for bypassing biometric authentication and device bindings inside Work Profiles.
Vwork detection status by Google Play Protect and major MDMs.
Correlation between the 1,469 compromised devices and 1,281 potentially compromised logins, as well as the success count of unauthorized transfers. Due to differing aggregation units, transfer success rates cannot be determined from the difference between the two.
15. Impact on SOCs and Organizations
For domestic organizations utilizing Work Profiles, unauthorized profile creation and app deployment are subject to investigation. Mobile SOCs should review available device, permission, and profile records, and cross-reference them with bank-side device registration and transaction records if unauthorized transfers are suspected. This report does not confirm that damage from the same attack has been observed in Japan.
16. Summary by Role
SOC: Correlate Gigabud deployment, net.yy.vwork, Work Profile creation, target app cloning, black screen overlays, and subsequent new device logins.
Administrators: Block APKs from outside official stores and restrict accessibility, overlays, and Work Profile creation for unknown apps via MDM.
Users: Avoid sideloading apps masquerading as airlines, tax services, or government agencies from external sites, and report unexpected Work Profile displays or duplicated banking apps.
Read original: https://dev.to/anoymask/gigabud-vwork-account-takeover-via-android-banking-app-cloning-in-work-profiles-3fji
← Previous
GitLab CVE-2026-85706: Active Scanning Targeting Pre-Authentication File Read
Next →
Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says
Related
The 2-Hour Bash Bug That Taught Me How Quoting Actually Works
DevOps
0
Dev.to (EN Zone)
Choosing free on-prem git server - Gitea is the winner!
DevOps
0
DEV Community
Daily Dose of DevOps — Terraform remote state explained
DevOps
0
DEV Community
[Showoff Saturday] Mac MCP: background browser automation and live agent sessions on macOS
DevOps
0
Reddit r/webdev
Comments0
No comments yet — be the first