Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
A bank checks the device, finds it clean, approves the transfer. The problem is it's looking in the wrong profile.
The GoldFactory group has equipped the Android trojan Gigabud with Vwork, a weaponized fork of the open-source app cloner Shelter. According to Group-IB research — reported by Infosecurity Magazine, Cyber Security News and GBHackers — Vwork clones banking apps into a hidden Android Work Profile, isolating fraudulent sessions from signature-based detection in the personal profile.
"the point is detection isolation" — Group-IB via Infosecurity Magazine
Full infection chain confirmation is limited to the Indonesian market, where researchers observed approximately 1,469 compromised devices between February and July 2026.
- Vwork is a weaponized fork of Shelter, a legitimate open-source app cloner, modified by GoldFactory to expose cloning functions as programmatically callable APIs without user interaction.
- The package name
net.yy.vworkis referenced in Gigabud samples, which command Vwork via three dedicated C2 instructions:initVwato provision the profile,cloneAppto duplicate the target banking app, anduploadCloneAppsto exfiltrate the list. - Cloning requires a token from an external authorization server retrieved by Gigabud, indicating intentional toolkit design.
- In Indonesia, February–July 2026, Group-IB detected approximately 1,281 potentially compromised logins and estimated losses of approximately $960,939, figures the group explicitly defines as indicative and not representative of the full scope.
How Vwork Turns Shelter Into an Evasion Tool
Shelter is a legitimate open-source application that leverages the Android Work Profile API to clone apps into an isolated environment, typically to separate personal and corporate data on BYOD devices. Group-IB identifies Vwork as a weaponized fork with specific operational modifications: it removes cross-profile interaction restrictions, alters file-sharing behavior, supports sideloading, limits the Accessibility service in the provisioned profile, and hides its own icon from the launcher.
The decisive modification is the exposure of cloning functions as an API interface. Shelter requires direct user interaction; Vwork allows Gigabud to invoke cloning remotely via C2 commands with the vwa- prefix for app identifiers. This shift transforms a productivity tool into a silent component of criminal infrastructure.
Signature Blindness When the Profile Changes
"apps in one profile are largely invisible to signature-based detection in another, so an alert raised in the personal profile does not fire in a work profile created afterwards" — Group-IB via Infosecurity Magazine
Android's Work Profile is architecturally designed to guarantee isolation: apps, data, and permissions remain confined in a silo separate from the personal profile. Group-IB emphasizes that this separation, intended as an enterprise security measure, becomes a tool for "laundering" fraudulent sessions in GoldFactory's hands.
A banking app cloned in the work profile appears to the bank as a fresh installation on a clean device, while the malware that orchestrated the cloning remains in the personal profile with its accessibility and overlay permissions. Security systems monitoring the personal profile do not propagate alerts into the subsequently created Work Profile. This is not a bug to patch: it is an abuse of legitimate architecture.
The Attack Chain and Observed Data
Gigabud spreads via phishing sites, messengers, and social media impersonating airline, tax authority, or government apps. On launch it requests accessibility access, overlay permission, and battery optimization exemption. During fraud, a black screen hides activity while fake login screens capture credentials and invisible overlays intercept unlock codes.
Vwork-compatible samples target 11 countries: Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, Turkey, and an unspecified GCC state. However, full infection chain confirmation with Vwork is limited to Indonesia. In that market, during February–July 2026, Group-IB observed approximately 1,469 compromised devices, approximately 1,281 potentially compromised logins, and estimated losses of approximately $960,939. The source stresses these figures "reflect observed activity rather than the full scope."
What to Do Now
Group-IB has identified six behavioral signals to detect Vwork's cross-profile abuse. Financial institutions operating in targeted markets should integrate them into their fraud detection systems.
First: monitor for work profile creation not configured by the user on devices with banking apps installed. Second: detect markers of banking apps present in both profiles with the same identifier but different installation states. Third: flag isolated environments that are empty or contain a single banking app without enterprise correspondence. Fourth: flag accessibility abuse patterns concentrated in the personal profile immediately preceding work profile creation. Fifth: correlate persistent overlay permissions with battery exemptions in non-banking apps. Sixth: verify the presence of the net.yy.vwork package or vwa- prefixes in system logs.
For users, the defensive line remains the systematic refusal of accessibility and overlay permissions from unverified apps, regardless of their purported source. The phishing delivering Gigabud mimics airlines and tax authorities: none of these entities ever requires accessibility access.
Why This Matters
Banks have spent millions on app attestation and signature-based detection. Vwork blinds them by design, not by vulnerability. The Work Profile is a legitimate Android enterprise feature; the problem is that banking defenses are built on the assumption that a clean device in the personal profile means a legitimate user.
The external token required for cloning indicates GoldFactory designed Vwork as an integrated toolkit, not an opportunistic exploit. This level of engineering suggests the cross-profile tactic will be replicated and refined. Indonesia is the first confirmed market; the other 10 targeted countries remain exposed.
The measure of risk is not in the $960,939 observed alone, a figure Group-IB explicitly defines as non-representative. It lies in the demonstration that Android's architectural isolation, when weaponized, can nullify entire categories of anti-fraud investment. Banks must now watch both profiles — or lose sight of the theft.
Sources: Infosecurity Magazine; Cyber Security News; GBHackers. Technical data and impact figures derive from Group-IB research reported by the cited outlets.
Information is based on the cited source and current as of publication.
Sources
- https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/
- https://cybersecuritynews.com/hackers-clone-banking-apps/
- https://www.cryptika.com/hackers-clone-banking-apps-into-hidden-android-work-profiles-to-evade-fraud-detection/
- https://gbhackers.com/gigabud-banking-malware/
- https://cybersecuritynews.com/golddigger-gigabud-malware-airlines/
- https://cybersecuritynews.com/toxicpanda-android-malware/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.