Android banking malware has found a way to hide its fraud in plain sight. Researchers at Group-IB say the Gigabud banking Trojan copies a victim's banking app into a separate work profile, then runs fraudulent transactions there, according to Malwarebytes Labs. Because Android normally keeps work and personal profiles isolated, the malicious activity sits apart from the malware's other traces on the device, and the company warns this can weaken bank anti-fraud systems and in-app malware detection that do not correlate events across profiles.
The trick works because Android work profiles are built to separate work apps and data from personal ones, so apps in different profiles cannot see each other. That isolation means a banking app or security tool may never connect malware running in the personal profile with the cloned app's activity in the work profile. Group-IB describes the result as a broken detection link between the personal-profile malware and the work-profile transaction.
Read more: Google Clones Apple Handoff Feature for Android 17 with New Continue On Tool
Gigabud gets there by installing Vwork, a modified version of the open-source tool Shelter, which normally isolates apps or runs second copies inside a work profile. The altered build lets Gigabud control those functions remotely. Vwork strips away the protections on cross-profile interaction and exposes components that set up the profile, clone and list apps, and open them, and it also hides its own launcher icon. The operator then uses it to create a new work profile and clone a chosen banking app into it.
Victims are drawn in by sideloading a fake airline, tax, or government app pushed through phishing sites, messages, or social media. Once installed, the app asks for Accessibility access, overlay permission, and an exemption from battery optimization, permissions that together allow remote interaction and credential theft through overlays. The sideloaded app also checks which apps are installed and reports banking targets back to its operator. Fake banking-login overlays then capture banking credentials and the device PIN.
From the new profile, the operator can transact remotely and can optionally hide the activity behind a black screen. In effect, Gigabud turns Android's profile separation into a fraud tool, leaving a gap between the malware alert raised in one profile and the fraudulent session running in another.
The advice for users is straightforward. Install banking apps only from the official store or a publisher's direct link, and treat any unsolicited request to install an APK as a likely scam. Do not grant Accessibility or display-over-other-apps permission to airline, tax, delivery, or government apps, since overlays require explicit user approval on modern Android and such requests are a red flag. Running up-to-date, real-time anti-malware on an Android device is also recommended.
If an APK has already been granted Accessibility, Malwarebytes advises reaching the bank through a trusted channel, revoking those permissions, uninstalling the app, and considering a factory reset. A second copy of a banking app deserves particular scrutiny, and while a separate work profile on its own is not proof of compromise, a cloned banking app in one is definitely suspicious. Malwarebytes detects Gigabud components under seven detection names.
The finding lands in a busy stretch for Android threats. Earlier this month, Malwarebytes reported that StreamRat ads on Meta and TikTok reached about 570,000 Meta users, a figure that counts ad exposure rather than infections, and that the Spanish-speaking targets were mostly observed in Spain, with one campaign running from June 11 to July 3, 2026. In February, researchers documented the first Android malware using generative AI for persistence, with ESET finding that PromptSpy relied on Google Gemini.













