Technology Sep 12, 2026 · 8 min read

Gigabud / Vwork: Account Takeover via Android Banking App Cloning in Work Profiles

1. Basic Information Original Title: Indonesia Hit by Android Banking App Cloning Campaign Source: Dark Reading, Group-IB Publication Date: 2026-09-11 Severity: High Basis for Severity: Actual financial losses and numerous compromised devices have been confirmed, and the enterprise Work...

DE
DEV Community
by Anoymask
Gigabud / Vwork: Account Takeover via Android Banking App Cloning in Work Profiles

1. Basic Information

2. Executive Summary

Gigabud obtains accessibility permissions, deploys Vwork, and clones banking apps inside an Android Work Profile. It leverages the separation from the personal profile to register the device with the bank, enabling remote control and unauthorized fund transfers behind a black screen.

3. Attack Flow

Flow 1: Banking App Cloning Using Vwork via Gigabud

  1. The victim sideloads an APK disguised as an airline, tax, or government app.
  2. Gigabud requests accessibility permissions, display over other apps, and ignore battery optimizations. It collects credentials through a fake banking login screen and screen lock codes through another mechanism.
  3. C2 commands deploy Vwork and create an Android Work Profile.
  4. Vwork clones the banking app into the Work Profile, and Gigabud relays operation commands. Group-IB's confirmed examples also include deploying modified versions disguised as legitimate banking apps.
  5. The attacker registers the cloned app as a new device behind a black screen overlay and transfers funds without authorization.

4. Attacker Positioning and Execution Location

  • External attacker who induces the victim to sideload the APK and grant permissions.
  • Once permissions are obtained, the attacker remotely controls the device screen and apps, operating the banking apps within the Work Profile.

5. Visibility for Victims and Administrators

Victims

  • Requests to install fake brand apps, permission prompts for accessibility, display over other apps, and ignore battery optimizations.
  • Unexpected briefcase icon for the Work Profile, duplicated banking apps, and a black screen during operation.

Administrators

  • APKs from unofficial sources, net.yy.vwork, rapid Work Profile creation, and banking app cloning.
  • Linking of new profiles and new devices from the same physical device, along with unusual transfers.

6. Success and Failure Conditions

Success Conditions

  • The user sideloads the malicious APK and grants accessibility and other permissions.
  • The device allows the creation of a Work Profile and the cloning of banking apps.
  • The bank does not carry over personal profile risk signals to the authentication of the new profile.

Failure Conditions

  • Inference: Restricting APK installation from external sites and unauthorized app permissions via device policies can block the reported delivery vector.
  • Inference: On managed devices, restrict unauthorized accessibility usage and Work Profile creation based on MDM capabilities.
  • Inference: Linking new device registration and transfer risk assessments on the bank side, and requiring additional authentication when necessary, can curb misuse after app cloning.

7. What Happens Upon Success

  • Theft of mobile banking credentials and transaction authentication.
  • Remote control and unauthorized fund transfers that are hard for the user to notice.
  • Inference: The same technique may be repurposed for other banking and payment apps. The targets and scope of success depend on the app and bank controls.

8. Observable Logs

Email

  • Group-IB reports APK distribution via social engineering such as SMS. Review messages and URLs provided by users. May not appear in corporate email logs.

Proxy / SWG / DNS

  • Inference: Communications to fake airline, tax, and government domains, Gigabud C2, and APK download sources.

Endpoint / EDR

  • Inference: Deployment of net.yy.vwork, accessibility service registration, overlays, ignoring battery optimizations, Work Profile creation, and app cloning.

Identity / IdP

  • Inference: Check new device registrations, changes in authentication methods, and login origins in bank records. The mapping between physical devices and profiles depends on available identifiers and bank cooperation.

SaaS / Cloud

  • Inference: New device registration for mobile banking, adding recipients and making transfers inconsistent with user behavior.

Network

  • Inference: C2 where Gigabud relays Vwork commands, and continuous communication associated with remote screen control.

9. Attack Success Criteria

Below are the ranges confirmed by public information and the determination criteria used in internal investigations.

  • User Action Confirmed: Public Info: Gigabud distribution utilizes APK installation from external sites and permission grants. Group-IB has confirmed the infection vector on the device.
  • Initial Execution Confirmed: Public Info: The deployment of Vwork and banking apps following Gigabud, using Work Profiles, has been reported.
  • Information Theft or Session Compromise Confirmed: Public Info: Credential theft via fake login screens has been reported. The 1,281 cases represent potentially compromised logins and not confirmed unauthorized transfer counts.
  • Subsequent Compromise Confirmed: Public Info: Group-IB reported banking operations on victim devices and estimated losses. Individual cases require confirmed unauthorized transfers in bank transaction records, and APK deployment or profile creation alone does not constitute successful transfer.

10. Investigation Playbook

Triggers

  • Granting accessibility to an unknown APK, net.yy.vwork, unexpected Work Profile, or duplicated banking apps.

Initial Response

  • Preserve the APK acquisition path, package, signature, permissions, profile creation time, and bank login time.

Device / Server

  • Check Android package lists, accessibility services, device policy management apps, overlays, Work Profiles, and ignored battery optimizations.

Authentication / Cloud

  • Investigate bank-side device IDs, profiles, device bindings, login IPs, added recipients, and transfer history.

Subsequent Operations

  • Inference: Check for additional APKs, cloning of other banking and wallet apps, and access permissions/usage traces for SMS. Notification theft is not treated as a confirmed behavior in this material.

Containment

  • Isolate the device from the network, contact the bank to invalidate sessions, device bindings, and credentials.
  • Preserve evidence, and wipe/re-enroll corporate devices according to management procedures. Check other devices using the same account.

Determination Categories

  • Separate APK contact, permission grants, Work Profile creation, successful bank authentication, and unauthorized transfers.

11. Defense and Detection Ideas

Single Event

  • Inference: Work Profile creation on non-MDM managed devices, or detection of net.yy.vwork.
  • Inference: Simultaneous grant of accessibility and overlay permissions to an unknown app.

Time-Series Correlation

  • Inference: Correlate sideloading -> accessibility -> Vwork -> profile creation -> banking app cloning -> new device authentication -> transfer.

Hunting

  • Inference: Enumerate Work Profile creation sources, cloned high-value apps, and abnormal accessibility services across Android device fleets.

Log Gaps

  • When bank-side and device-side records cannot be correlated, it becomes difficult to confirm whether different profiles belong to the same physical device or to establish the link between registration and transfer.

Priority Countermeasures

  • Inference: Prioritize blocking sideloading, accessibility allowlists, Work Profile management, and integrating financial-side device bindings.

12. Facts / Inference / Hypothesis

Facts

  • Group-IB reported approximately 1,469 compromised devices, 1,281 potentially compromised logins, and an estimated $960,000 in losses observed in Indonesia between February and July 2026. These values reflect Group-IB's observation scope and do not represent the total regional damage scale.
  • Gigabud is distributed as fake airline, tax, and government apps outside official stores, and requests accessibility, display over other apps, and ignore battery optimizations.
  • Minutes after installation, Gigabud deploys Vwork (net.yy.vwork) and operates it using C2 commands such as initVwa, cloneApp, and uploadCloneApps.
  • Vwork is a modified version of the open-source tool Shelter, which clones target banking apps into a Work Profile. Vwork itself has no C2, and Gigabud relays its commands.
  • Attackers remotely operate the cloned apps behind a black screen overlay, appearing to the bank as a new device and new profile.

Inference

  • If infection, overlay, and accessibility signals from the personal profile are not shared with the banking app assessment in the Work Profile, traditional device-level rules may be bypassed.
  • Time-series detection spanning Work Profile creation, app cloning, device registration, and fund transfers is effective.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "Unanswered Questions and Further Investigation".

13. MITRE ATT&CK Mapping

  • T1660 Phishing (Confidence: high): Induces deployment using fake airline, tax, and government apps.
  • T1406.002 Obfuscated Files or Information: Software Packing (Confidence: medium): Group-IB reports that both Vwork and related Gigabud samples are packed with dpt-shell.
  • T1626.001 Abuse Elevation Control Mechanism: Device Administrator Permissions (Confidence: medium): Group-IB reports that Vwork and Gigabud request device administrator privileges. This is a separate behavior from the abuse of accessibility permissions.
  • T1453 Abuse Accessibility Features (Confidence: high): Uses accessibility as the foundation for screen operation, information retrieval, and remote control.

14. Unanswered Questions and Further Investigation

  • Target app lists and financial losses by country and bank.
  • Specific conditions for bypassing biometric authentication and device bindings inside Work Profiles.
  • Vwork detection status by Google Play Protect and major MDMs.
  • Correlation between the 1,469 compromised devices and 1,281 potentially compromised logins, as well as the success count of unauthorized transfers. Due to differing aggregation units, transfer success rates cannot be determined from the difference between the two.

15. Impact on SOCs and Organizations

For domestic organizations utilizing Work Profiles, unauthorized profile creation and app deployment are subject to investigation. Mobile SOCs should review available device, permission, and profile records, and cross-reference them with bank-side device registration and transaction records if unauthorized transfers are suspected. This report does not confirm that damage from the same attack has been observed in Japan.

16. Summary by Role

  • SOC: Correlate Gigabud deployment, net.yy.vwork, Work Profile creation, target app cloning, black screen overlays, and subsequent new device logins.
  • Administrators: Block APKs from outside official stores and restrict accessibility, overlays, and Work Profile creation for unknown apps via MDM.
  • Users: Avoid sideloading apps masquerading as airlines, tax services, or government agencies from external sites, and report unexpected Work Profile displays or duplicated banking apps.
DE
Source

This article was originally published by DEV Community and written by Anoymask.

Read original article on DEV Community
Back to Discover

Reading List