Gigabud is an Android malware family associated with mobile financial fraud campaigns across parts of Asia-Pacific and Latin America, including Thailand, Indonesia, Vietnam, the Philippines, Peru, and Malaysia. It has been described primarily as an Android remote access trojan, with related family variants also used as fake loan applications for harvesting victim-supplied personal and financial data. The malware has been linked to campaigns impersonating government agencies, airlines, banks, and lending services, and has also been connected to activity attributed to the Chinese-speaking cybercrime group GoldFactory.
Gigabud is commonly distributed through phishing infrastructure and direct messaging lures that persuade victims to install Android applications from outside official app stores. Campaigns have used fake landing pages, social-network and messenger delivery, SMS-based lures, and direct APK sharing. The applications typically masquerade as legitimate financial or government services and request high-risk permissions including Accessibility, screen recording, overlay, and installation-related privileges.
A defining characteristic of Gigabud.RAT is its use of Android Accessibility Services together with screen capture to enable remote device interaction and theft of sensitive information. Rather than relying solely on traditional overlay techniques, it can stream or record the victim’s screen, perform gestures on the device, open targeted applications, and automate interactions that can bypass normal user-driven authentication flows, including some two-factor authentication scenarios. Reported functionality includes remote command execution within the app context, collection of installed application data, credential theft from banking workflows, clipboard manipulation to replace payment card data, SMS sending, and newer accessibility-based keylogging modules aimed at stealing banking passwords.
Related Gigabud samples have also displayed fake banking prompts and loan workflows to collect credentials and extensive identity data. The Gigabud.Loan variant has been used as a fraudulent lending application that solicits information such as identity details, contact information, income data, bank card information, document images, and digital signatures, but lacks the full remote-access feature set of Gigabud.RAT.
Operationally, Gigabud campaigns have shown victim-validation logic and staged activation behavior. Some samples reportedly delay malicious actions until the victim is approved or authorized by the operator, suggesting a fraud-centric workflow designed to focus resources on viable targets and reduce exposure. The malware family has been observed in sustained campaigns from at least 2022 onward, with numerous distinct samples identified and evidence of geographic expansion over time.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...resulting in the deployment of a remote access trojan like Gigabud, MMRat, or Remo, which surfaced earlier this year using the same tactics as GoldFactory.
1 distinct technique documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware family referenced as connected (operationally) to GoldDigger; no further technical detail in the excerpt.
Android banking trojan targeting customers of financial institutions in Indonesia and Malaysia.
Android banking trojan targeting customers of financial institutions in Indonesia and Malaysia; further technical details not provided in the text.
A remote access trojan deployed via fake banking apps, used to gain remote control over infected Android devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.