Gigabud is an Android banking remote-access trojan active since 2022 and associated with the Chinese-speaking financially motivated GoldFactory cybercrime group. It is distributed through fraudulent Android applications impersonating government agencies, tax services, airlines, financial institutions, and loan services. Victims are typically directed to sideload these applications through phishing sites, messaging platforms, SMS, and social-media lures.
After installation, Gigabud requests Accessibility access, overlay privileges, screen-recording capability, and exemption from battery optimization. These permissions enable operators to remotely interact with the device, enumerate installed applications, record the screen, display counterfeit banking-login prompts, capture banking credentials and device unlock codes, send SMS messages, alter clipboard data, and automate banking activity. Some versions include Accessibility-based keylogging functionality focused on banking credentials and can obscure fraudulent activity by displaying a black screen.
Recent Gigabud operations deploy Vwork, a weaponized modification of the Android work-profile utility Shelter. Vwork can create an isolated Android Work Profile and clone or install a targeted banking application within it under Gigabud operator control. This profile separation can weaken fraud and malware-detection controls that do not correlate activity between personal and work profiles, allowing fraudulent banking sessions to appear detached from malware present in the primary profile. Confirmed activity has affected Indonesian users, while compatible samples have targeted victims across Southeast Asia, South Asia, the Middle East, Africa, and Latin America. Gigabud also includes the related Gigabud.Loan variant, a fraudulent loan application designed to harvest victims’ personal and financial information rather than provide full remote-access functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it.”
13 distinct techniques documented for this family, organized by ATT&CK tactic.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan used for mobile-banking fraud. It leverages Android Work Profile isolation to clone a target banking app, separating the cloned app and subsequent payment activity from the victim's personal profile and undermining fraud correlation. It can provision the profile, clone target apps, report cloned-app information, and requires an external authorization-server token before cloning.
Android banking trojan that lures victims into sideloading fake apps, abuses Accessibility and overlay permissions to steal banking credentials and device PINs, and installs Vwork to create a work profile containing a cloned banking app. Operators can remotely conduct and conceal fraudulent transactions from the isolated profile.
Android banking trojan that is delivered through sideloaded fake airline, tax, or government applications. It abuses Accessibility, overlay, and battery-optimization-exemption permissions to support remote device interaction, banking-login overlays, theft of banking credentials and device PINs, and identification of installed banking applications. It uses Vwork to create a work profile and clone a targeted banking app, allowing operators to conduct fraudulent transactions from a profile separate from malware activity in the personal profile.
Android banking trojan deployed with the Vwork app-cloning add-on. The combination hides the trojan through an isolated Android Work Profile while enabling remote control of compromised devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.