$ techbeacon▋
Malware

GoldFactory Deploys Weaponized Vwork Fork to Boost Gigabud Banking Trojan’s Stealth

GoldFactory Deploys Weaponized Vwork Fork to Boost Gigabud Banking Trojan’s Stealth

Cyber‑crime group GoldFactory has taken its Android banking malware, known as Gigabud, a step further by integrating a maliciously modified version of the open‑source Shelter app, dubbed Vwork. The new component expands the trojan's ability to avoid detection on compromised devices, according to analysis first shared by the GBHackers community.

Vwork operates by exploiting Android's Work Profile feature, a sandbox intended for separating personal and corporate data. By cloning targeted banking applications into this managed profile, the malware can interact with the apps while remaining hidden from security tools that monitor the primary user space. The approach mirrors legitimate use cases of Shelter, but the fork adds code that silently redirects financial transactions to attackers.

Gigabud has been active for several years, primarily relying on overlay attacks and key‑logging to capture credentials from popular banking apps. Prior versions were often uncovered by antivirus products that flagged known signatures or suspicious permission requests. The addition of Vwork’s profile‑level isolation represents a shift toward more sophisticated evasion, allowing the trojan to persist even on devices with up‑to‑date security patches.

The development raises concerns for both consumers and financial institutions. By operating inside a work profile, the malware can bypass many endpoint‑detection solutions that focus on the personal profile, potentially extending the window of exposure. Banks may see an uptick in fraudulent transactions that originate from devices appearing clean under conventional scans, prompting a reevaluation of mobile security guidelines.

Security researchers are urging Android users to review the apps granted work‑profile permissions and to disable the feature if it is not needed. Meanwhile, Google has been notified of the Vwork abuse and may consider tightening the API that allows third‑party apps to manage work profiles. As threat actors continue to weaponize legitimate development tools, the cybersecurity community expects further adaptations that blend open‑source utilities with malicious intent.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related