CyberSecurity SEE

Gigabud Employs Android App Cloning to Avoid Fraud Detection

Gigabud Employs Android App Cloning to Avoid Fraud Detection

The Rise of the Gigabud Android Banking Trojan: A New Threat to Financial Security

The digital landscape continues to evolve, and with it, the threats to financial security are becoming increasingly sophisticated. Recently, researchers at Group-IB uncovered alarming details about the Gigabud Android banking trojan, which has now been enhanced to clone banking applications into a separate Android work profile. This development presents a unique way for fraudsters to sever the connection between malware alerts and the transactions that follow, making it even more challenging for law enforcement and financial institutions to combat this form of cybercrime.

In a research report released on September 9, Group-IB highlighted the relationship between Gigabud and Vwork, an adapted version of the open-source Android cloning app Shelter. The research indicated that both tools are attributed to the cybercriminal group known as GoldFactory, suggesting that they have either developed these tools themselves or customized existing ones for their malicious intents.

The findings also revealed that the full infection chain of Gigabud had only been conclusively confirmed within devices located in Indonesia. However, the samples associated with Gigabud, tailored to operate in conjunction with Vwork, were found to be targeting an alarming array of countries. Among these were Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye, illustrating the global reach and potential impact of this threat.

Understanding Vwork’s Functionality

Vwork employs Android’s Work Profile feature to enable the cloning of apps within an isolated environment. Unlike its predecessor, Shelter, which is designed to be used by device owners, Vwork takes a different approach. It exposes its app cloning capabilities in a way that any application on the device can access it. This innovative method allows cybercriminals to exploit the underlying technology effectively.

Intriguingly, the samples of Gigabud that work in tandem with Vwork incorporate specialized code that includes three new commands. These commands serve distinct roles: provisioning the work profile, cloning a specified app, and reporting back on the cloning process. In order to initiate cloning, Gigabud retrieves a token from an external authorization server, adding a layer of complexity to its operation.

Group-IB emphasizes that the primary goal behind this method is to establish what they term "detection isolation." By creating applications in one profile that are largely invisible to signature-based detection mechanisms in another, the malware can operate without raising immediate alarms. Consequently, any malware alert triggered in a user’s personal profile does not translate into an alert for the work profile, which is created subsequently.

Operators utilizing this malware typically undertake a methodical approach: they first install the malware, wait for an opportune moment, and then clone the banking application into the newly established work profile to conduct transactions. When these transactions occur, they appear to come from an unrecognized device without any prior malware history, complicating the task for banks trying to detect and thwart fraud.

The Mechanics of Fraud

The fraud methods employed by these malicious actors are both clever and alarming. Fake login screens are deployed to capture users’ banking credentials, while an invisible overlay captures the lock screen code. During the fraudulent transactions, a black screen is employed to obscure activities on the handset, effectively concealing the fraudulent proceedings from the user’s view.

In Indonesia, between February and July 2026, Group-IB observed approximately 1,469 compromised devices along with 1,281 potentially compromised login credentials. The estimated financial losses during this period reached around $960,939, though researchers cautioned that these figures are indicative rather than comprehensive of the broader regional impact.

Active since 2022, Gigabud often reaches its targets through phishing websites, messengers, and social media, masquerading as legitimate applications from airlines, tax authorities, or government bodies. Upon first launching, the malware seeks permissions that grant it access to the device’s features, such as accessibility services, overlay permissions, and battery exemptions. The request for accessibility services is particularly crucial as it allows the operator to exert control over the compromised device.

Recommendations for Financial Institutions and Users

Group-IB has outlined a series of behavioral signals that banks and financial institutions should monitor closely. These include the emergence of a work profile on a user’s phone that they did not set up, matches between banking app indicators across profiles, and the presence of an otherwise empty isolated environment. Furthermore, they identified accessibility access requested from apps that have no justifiable reason for needing it.

If two or more of these behavioral signals are detected, they should be treated as indicators of a high-risk session. To combat such threats effectively, Group-IB also recommends implementing device binding mechanisms to prevent unauthorized logins from authorizing payments. Additionally, users are advised to download applications exclusively from official app stores to minimize their risk of infection.

As the landscape of mobile banking continues to evolve, so too must the strategies employed to safeguard personal and financial information from emerging threats like the Gigabud trojan. The collaboration between cybersecurity experts and financial institutions will be crucial in fortifying defenses against these increasingly sophisticated types of cybercrime.

Source link

Exit mobile version