A GoldFactory-linked Android banking-fraud operation is using the Gigabud remote-access trojan and Vwork, a modified version of the open-source Shelter app cloner, to duplicate banking apps inside concealed Android work profiles. The isolated profile makes fraudulent banking sessions appear clean by separating them from malware indicators and risk signals associated with a victim’s personal profile, helping attackers bypass bank fraud detection, take over accounts, and initiate unauthorized transfers.
Victims are lured through phishing sites, messaging apps, and social-media posts to sideload fake airline, tax, government, or banking applications. Gigabud abuses Accessibility, overlay, and battery-optimization-exemption permissions for remote control, credential theft, installed-app discovery, banking overlays, and lock-screen code capture. Group-IB identified compatible activity in multiple countries; in Indonesia, it recorded 1,469 compromised devices, 1,281 potentially compromised logins, and an estimated $960,939 in losses between February and July 2026.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Between February and July 2026, Group-IB observed approximately 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated losses of about $960,939.
The Gigabud Android remote-access banking trojan has been active since 2022.
The reporting identified Vwork package ID net.yy.vwork and published SHA-256 hashes for Gigabud, Vwork, and modified banking-application samples associated with the campaign.
Group-IB linked Gigabud activity using Vwork, a modified Shelter application cloner, to GoldFactory. The operation uses concealed Android work profiles to host cloned or tampered banking apps and separate fraudulent sessions from malware risk signals in the personal profile.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
9 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcecommunity.gurucul.com
Open sourcethehackernews.com
Open sourceinfosecurity-magazine.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcegroup-ib.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.