← Back to Crime & Security

New Gigabud Trojan Evades Fraud Detection by Cloning Banking Apps

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

JAKARTA — A sophisticated new strain of Android banking malware known as Gigabud is actively deploying a novel evasion technique designed to bypass financial fraud detection systems. The malicious software, attributed to the threat actor group GoldFactory, isolates cloned versions of legitimate banking applications within separate work profiles on infected devices, effectively severing the digital link between security alerts and fraudulent transactions.

The campaign was identified on September 9, 2026, targeting users across seven nations: Indonesia, Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye. Unlike traditional trojans that overlay fake login screens or operate directly alongside genuine applications, Gigabud leverages the Android operating system's built-in work profile feature to create a sandboxed environment. Within this isolated space, the malware replicates the interface of popular banking apps, tricking users into entering credentials while remaining invisible to security tools monitoring the device's primary user profile.

This architectural shift represents a significant evolution in mobile financial crime. By compartmentalizing the malicious activity, the developers prevent fraud detection algorithms from correlating the presence of the malware with suspicious transaction attempts. Security mechanisms that typically flag anomalies when a banking app interacts with known malicious processes are rendered ineffective because the cloned application operates in a distinct, authorized container.

GoldFactory, the group behind the operation, has refined its approach to exploit the trust users place in system-level features. The work profile, originally designed by Google to allow employers to manage corporate data separately from personal information, is being weaponized to shield illicit activities from scrutiny. Once inside this isolated environment, the trojan captures login credentials and session tokens, granting attackers direct access to victim accounts without triggering standard behavioral alerts.

The geographic scope of the attack indicates a coordinated effort targeting regions with high mobile banking adoption rates. In Indonesia and Brazil, where digital payments have surged in recent years, the impact could be substantial if users are unaware of the work profile's existence. The malware often arrives through malicious advertisements or compromised third-party app stores, prompting users to install what appears to be a legitimate utility before the cloning process begins.

As security vendors race to update detection signatures for this specific behavior, the effectiveness of current mobile defense strategies remains uncertain. The use of legitimate system features by attackers complicates the development of heuristic defenses that rely on identifying malicious code patterns. Questions remain regarding the total number of compromised devices and whether financial institutions have successfully intercepted transactions initiated through these isolated profiles. With the malware actively spreading across multiple continents, the window for user education and technical mitigation is narrowing rapidly.

Discussion

0 / 2000