Vwork: Weaponized Open-source Software as an Addon for Gigabud
Gigabud is an Android remote access banking trojan active since 2022, attributed to GoldFactory group, targeting victims across Southeast Asia, South Asia, Middle East, Africa and Latin America. The malware now utilizes Vwork, a weaponized fork of the open-source app cloning application Shelter, to evade detection by creating isolated work profiles. After initial Gigabud infection, Vwork is installed to clone banking applications into the work profile, hiding malicious activity from signature-based detection in application security SDKs. Between February and July 2026, approximately 1,469 compromised devices and 1,281 potentially compromised logins were observed in Indonesia alone, with estimated losses of roughly $960,939. The infection chain involves social engineering through phishing sites delivering fake apps disguised as legitimate services, followed by credential theft through overlays and remote-controlled fraudulent transactions executed within cloned banking apps.
AI Analysis
Technical Summary
Gigabud is an Android banking trojan attributed to the GoldFactory group, active since 2022 and targeting multiple regions including Southeast Asia and Latin America. It employs Vwork, a modified version of the open-source Shelter app cloning tool, to create isolated work profiles on infected devices. This technique allows Gigabud to clone legitimate banking apps into these profiles, effectively hiding malicious activities from signature-based detection mechanisms in application security SDKs. The infection vector involves social engineering via phishing sites that deliver fake apps posing as legitimate services. Once installed, the malware steals credentials through overlay attacks and performs remote-controlled fraudulent transactions within the cloned banking apps. Data from February to July 2026 shows a substantial number of compromised devices and logins in Indonesia alone, with financial losses nearing one million USD.
Potential Impact
The malware enables attackers to stealthily steal banking credentials and conduct fraudulent transactions by hiding malicious activity within cloned banking apps in isolated work profiles. This leads to significant financial losses for victims, as evidenced by nearly $1 million in estimated losses in Indonesia over a six-month period. The use of work profile evasion complicates detection by traditional security SDKs, increasing the risk of prolonged undetected compromise.
Mitigation Recommendations
No official patch or remediation is indicated. Mitigation should focus on user education to avoid phishing sites and fake apps, deploying advanced behavioral detection tools capable of identifying app cloning and work profile evasion techniques, and monitoring for suspicious banking transactions. Security teams should be aware of the use of work profile evasion by this malware to improve detection strategies. Since this is not a vulnerability with a patch, no direct fix is available.
Indicators of Compromise
- hash: cf7b54f98eb49463c41e3f7e1690a9aa
- hash: fd582c3b870e69861bfb36b2d990d93c8538e6a2
- hash: 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc
- hash: b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501
- hash: ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae
- hash: 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf
- hash: 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611
- hash: 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c
- hash: 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3
- hash: 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb
- hash: 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc
- hash: 19fbbf9cb32662f86b6ab00e59f7490d
- hash: d064fd7665977adfe76a48d733460a03
- hash: e24f150e02fba6d0cbbcfbf21b1347e5
- hash: 7e43538699f2610780b9d060937be36c08f3b257
- hash: d1a773b1cc3a3f756337ffb9c6d8cd6c13d2a14d
- hash: ddcfd1cbfd231c3b75d8a8b41fae379f0eebf4eb
- hash: 232939a64c11f6535ace11e260d5f811
- hash: 732ba148707ddb33200ca90e64f3d078
- hash: d747f766bc64667e68c51085995dc988
- hash: 1f36410ec83e0a613de517bcb358f98c9ea54ca2
- hash: 327687610688216c928ba14e3cd54dec9371b292
- hash: 4a9cc9e7aa2a746a033c83304faa25f3c4569b9f
Vwork: Weaponized Open-source Software as an Addon for Gigabud
Description
Gigabud is an Android remote access banking trojan active since 2022, attributed to GoldFactory group, targeting victims across Southeast Asia, South Asia, Middle East, Africa and Latin America. The malware now utilizes Vwork, a weaponized fork of the open-source app cloning application Shelter, to evade detection by creating isolated work profiles. After initial Gigabud infection, Vwork is installed to clone banking applications into the work profile, hiding malicious activity from signature-based detection in application security SDKs. Between February and July 2026, approximately 1,469 compromised devices and 1,281 potentially compromised logins were observed in Indonesia alone, with estimated losses of roughly $960,939. The infection chain involves social engineering through phishing sites delivering fake apps disguised as legitimate services, followed by credential theft through overlays and remote-controlled fraudulent transactions executed within cloned banking apps.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Gigabud is an Android banking trojan attributed to the GoldFactory group, active since 2022 and targeting multiple regions including Southeast Asia and Latin America. It employs Vwork, a modified version of the open-source Shelter app cloning tool, to create isolated work profiles on infected devices. This technique allows Gigabud to clone legitimate banking apps into these profiles, effectively hiding malicious activities from signature-based detection mechanisms in application security SDKs. The infection vector involves social engineering via phishing sites that deliver fake apps posing as legitimate services. Once installed, the malware steals credentials through overlay attacks and performs remote-controlled fraudulent transactions within the cloned banking apps. Data from February to July 2026 shows a substantial number of compromised devices and logins in Indonesia alone, with financial losses nearing one million USD.
Potential Impact
The malware enables attackers to stealthily steal banking credentials and conduct fraudulent transactions by hiding malicious activity within cloned banking apps in isolated work profiles. This leads to significant financial losses for victims, as evidenced by nearly $1 million in estimated losses in Indonesia over a six-month period. The use of work profile evasion complicates detection by traditional security SDKs, increasing the risk of prolonged undetected compromise.
Defensive Guidance
No official patch or remediation is indicated. Mitigation should focus on user education to avoid phishing sites and fake apps, deploying advanced behavioral detection tools capable of identifying app cloning and work profile evasion techniques, and monitoring for suspicious banking transactions. Security teams should be aware of the use of work profile evasion by this malware to improve detection strategies. Since this is not a vulnerability with a patch, no direct fix is available.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/"]
- Adversary
- GoldFactory
- Pulse Id
- 6aa1817931ae64493d38a05f
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashcf7b54f98eb49463c41e3f7e1690a9aa | — | |
hashfd582c3b870e69861bfb36b2d990d93c8538e6a2 | — | |
hash4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc | — | |
hashb769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 | — | |
hashae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae | — | |
hash112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf | — | |
hash9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 | — | |
hash1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c | — | |
hash0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 | — | |
hash66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb | — | |
hash61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc | — | |
hash19fbbf9cb32662f86b6ab00e59f7490d | — | |
hashd064fd7665977adfe76a48d733460a03 | — | |
hashe24f150e02fba6d0cbbcfbf21b1347e5 | — | |
hash7e43538699f2610780b9d060937be36c08f3b257 | — | |
hashd1a773b1cc3a3f756337ffb9c6d8cd6c13d2a14d | — | |
hashddcfd1cbfd231c3b75d8a8b41fae379f0eebf4eb | — | |
hash232939a64c11f6535ace11e260d5f811 | — | |
hash732ba148707ddb33200ca90e64f3d078 | — | |
hashd747f766bc64667e68c51085995dc988 | — | |
hash1f36410ec83e0a613de517bcb358f98c9ea54ca2 | — | |
hash327687610688216c928ba14e3cd54dec9371b292 | — | |
hash4a9cc9e7aa2a746a033c83304faa25f3c4569b9f | — |
Threat ID: 6aa23b04acd9273b49952e81
Added to database: 09/10/2026, 05:07:16 UTC
Last enriched: 09/10/2026, 05:23:46 UTC
Last updated: 09/11/2026, 15:00:04 UTC
Views: 28
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.