Vwork is a weaponized Android fork of Shelter, an open-source application-cloning utility based on Android Work Profiles. It exposes work-profile provisioning, application cloning, cloned-application enumeration, and application-launching functions to other applications through exported interfaces, rather than limiting operation to direct user control. Vwork can hide its launcher icon and requires server-supplied authorization for cloning operations.
Vwork has been used with the GoldFactory-associated Gigabud Android banking trojan. Following Gigabud infection, the trojan can direct Vwork to create an isolated Work Profile and clone a targeted banking application into it, including tampered banking applications observed in Indonesia. Separating the cloned application from the personal profile can weaken correlation between malware detections or device-risk signals and subsequent fraudulent banking activity. Vwork has no independent command-and-control capability in the observed operation and relies on Gigabud to invoke its functions and obtain cloning authorization. Activity involving the Gigabud-Vwork chain has targeted Android users across Southeast Asia, South Asia, the Middle East, Africa, and Latin America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Vwork is a fork of the open-source Android cloning application Shelter... Vwork exposes controls as an API allowing third-party applications perform cloning and related application management.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A weaponized fork of Shelter that abuses Android Work Profiles to clone applications into an isolated profile. Gigabud invokes it to provision a Work Profile, clone a specified banking application, and report the cloned application, using an authorization token retrieved from an external server. This supports fraud by isolating a cloned banking app from detections raised in the device's personal profile.
A modified Android app-cloning tool used with Gigabud. It creates an isolated and concealed work profile, clones a targeted banking application into that profile, hides its launcher icon, and reduces visible signs of fraud while helping attackers evade device-risk signals tied to the personal profile.
Modified Android app-cloning tool used with Gigabud. It creates an isolated and concealed Android work profile, clones a banking application into that profile, hides its launcher icon, and can be controlled by another application, helping operators conduct fraud in a clean-looking session separated from device-risk signals.
Weaponized Android Work Profile cloning application used as a Gigabud companion. It creates an isolated work profile, clones targeted banking applications, and exposes cloning and application-management functions to Gigabud through exported APIs, helping separate fraud activity from malware signals and evade signature-based detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.