$ techbeacon▋
Malware

Gigabud Trojan Deploys Android Work Profiles to Evade Banking App Defenses

Gigabud Trojan Deploys Android Work Profiles to Evade Banking App Defenses

Security researchers at Group-IB have uncovered a new tactic employed by the Gigabud banking trojan, in which the malware creates a dedicated Android work profile on compromised devices and installs a modified banking application inside that isolated space.

The malicious code first drops a secondary app that leverages Android's managed profile feature, a tool originally designed for separating personal and corporate data. Once the work profile is established, the trojan places a tampered version of a legitimate banking app, allowing it to operate outside the scrutiny of standard security checks performed by the original app.

According to the Group-IB report released on September 9, the use of work profiles provides the malware with a dual‑layered concealment: the malicious banking app runs in a sandbox that appears trustworthy to the operating system, while the primary user environment remains free of obvious signs of infection. This approach helps the trojan bypass detection mechanisms that rely on scanning the main user space for known malicious signatures.

Banking trojans have been a persistent threat on Android devices for years, often relying on techniques such as overlay attacks, keylogging, and code injection. The shift to work‑profile exploitation marks a notable evolution, reflecting attackers’ adaptation to tighter app vetting processes in the Google Play Store and increased awareness among users about mobile fraud.

Experts warn that the new method could complicate remediation efforts. Traditional anti‑malware tools may not have visibility into the managed profile unless they are granted specific enterprise permissions, and many users are unlikely to notice the extra profile, as Android hides it from the standard app drawer.

Group-IB recommends that users keep their devices updated, scrutinize any unexpected prompts to create a work profile, and consider employing security solutions that monitor both personal and managed spaces. Enterprises are also urged to enforce stricter policies on profile creation and to educate employees about the risks of installing unknown applications, even when they appear to come from trusted sources.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related