Gigabud Uses Vwork to Clone Banking Apps on Android

Brendan Smith
Brendan Smith - Cybersecurity Analyst
4 Min Read
A banking app and its hidden copy inside one Android phone.
A banking app and its hidden copy inside one Android phone.

Gigabud banking malware is using Vwork to put a banking-app clone inside an Android work profile. Group-IB’s September 9 report confirms the chain in Indonesia. Separating the banking app from malware in the personal profile can obstruct in-app malware checks; it does not make the whole phone universally invisible to security tools. [1]

The practical question is who created that extra environment. A profile you never requested deserves investigation before you use the phone for another banking session.

What the newly reported technique changes

Vwork is a modified Shelter fork controlled by Gigabud. The report documents remote fraud and a tampered bank-app copy. Samples support targeting beyond Indonesia; that is not confirmation of Vwork infections in every listed country. [1]

Vwork activation prompt and its entry in the Android file manager.
Vwork setup prompt and Files entry documented by Group-IB; the middle panel translates the Chinese prompt into English. Source [1].

The research image helps identify the setup screen. Do not activate the application to investigate it. A matching name is a lead for support staff, not a reason to download a sample or test a live banking account.

A work profile is not automatically malware

Google describes work profiles as a normal way to separate work applications and data from personal use. Work apps ordinarily have a briefcase badge and appear in a Work tab. A profile created by your employer or intentionally set up by you is not, by itself, evidence of this campaign. [2]

Compare what changed with what you actually approved. Write down the unfamiliar app’s name, when it appeared and whether you followed an installation link or permission tutorial. Do not confuse an unrelated service with the same name with the application shown in the report. If this is an employer-managed phone, give the timeline to IT before changing its management settings.

Check the phone and the bank account separately

  1. Stop sensitive activity on a suspect phone. Use another trusted device to contact your bank through its established support channel. Describe any unexpected transactions and the suspicious installation. Do not use a phone number supplied by the installer or a recovery advertisement.
  2. Review the device with supported tools. Google’s Android recovery guidance covers Play Protect, system and security updates, removal of untrusted apps and an account security check. If problems persist, it recommends manufacturer help or considering a reset. These are general recovery steps, not a Gigabud-specific guarantee. [3]
  3. Understand the deletion boundary. On a personally owned device, Google’s documented route is Settings → Passwords and accounts → Work → Remove Work Profile. Names vary. Removing the profile deletes its local apps and data; confirm it is unwanted first. On a company-owned phone, involve IT. [2]
  4. Do not mistake one successful removal for complete recovery. Ask support to review the original suspicious installation as well. A disappeared profile does not reverse a bank transfer or revoke an exposed account session. Keep the financial incident open until your bank has addressed it.

If a streaming advertisement led to an APK and additional permissions, the separate StreamRat installation and response guide explains how to record the stages. Similar lures do not establish the same malware family.

References

  1. Group-IB. Vwork: Weaponized Open-source Software as an Addon for Gigabud. September 9, 2026.
  2. Google, Android Enterprise Help. What is an Android Work Profile? Accessed September 12, 2026.
  3. Google Account Help. Remove malware or unsafe software on Android. Accessed September 12, 2026.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT, a remote access tool used in malware campaigns—helping readers make sense of the threat and work through cleanup without the extra headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?