Skip to main content

Vwork: Weaponized Open-source Software as an Addon for Gigabud

0
Medium
Published: 09/09/2026 (09/09/2026, 15:55:37 UTC)
Source: AlienVault OTX General

Description

Gigabud is an Android remote access banking trojan active since 2022, attributed to GoldFactory group, targeting victims across Southeast Asia, South Asia, Middle East, Africa and Latin America. The malware now utilizes Vwork, a weaponized fork of the open-source app cloning application Shelter, to evade detection by creating isolated work profiles. After initial Gigabud infection, Vwork is installed to clone banking applications into the work profile, hiding malicious activity from signature-based detection in application security SDKs. Between February and July 2026, approximately 1,469 compromised devices and 1,281 potentially compromised logins were observed in Indonesia alone, with estimated losses of roughly $960,939. The infection chain involves social engineering through phishing sites delivering fake apps disguised as legitimate services, followed by credential theft through overlays and remote-controlled fraudulent transactions executed within cloned banking apps.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 05:23:46 UTC

Technical Analysis

Gigabud is an Android banking trojan attributed to the GoldFactory group, active since 2022 and targeting multiple regions including Southeast Asia and Latin America. It employs Vwork, a modified version of the open-source Shelter app cloning tool, to create isolated work profiles on infected devices. This technique allows Gigabud to clone legitimate banking apps into these profiles, effectively hiding malicious activities from signature-based detection mechanisms in application security SDKs. The infection vector involves social engineering via phishing sites that deliver fake apps posing as legitimate services. Once installed, the malware steals credentials through overlay attacks and performs remote-controlled fraudulent transactions within the cloned banking apps. Data from February to July 2026 shows a substantial number of compromised devices and logins in Indonesia alone, with financial losses nearing one million USD.

Potential Impact

The malware enables attackers to stealthily steal banking credentials and conduct fraudulent transactions by hiding malicious activity within cloned banking apps in isolated work profiles. This leads to significant financial losses for victims, as evidenced by nearly $1 million in estimated losses in Indonesia over a six-month period. The use of work profile evasion complicates detection by traditional security SDKs, increasing the risk of prolonged undetected compromise.

Defensive Guidance

No official patch or remediation is indicated. Mitigation should focus on user education to avoid phishing sites and fake apps, deploying advanced behavioral detection tools capable of identifying app cloning and work profile evasion techniques, and monitoring for suspicious banking transactions. Security teams should be aware of the use of work profile evasion by this malware to improve detection strategies. Since this is not a vulnerability with a patch, no direct fix is available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/vwork-app-cloning-gigabud-goldfactory/"]
Adversary
GoldFactory
Pulse Id
6aa1817931ae64493d38a05f

Indicators of Compromise

Hash

ValueDescriptionCopy
hashcf7b54f98eb49463c41e3f7e1690a9aa
hashfd582c3b870e69861bfb36b2d990d93c8538e6a2
hash4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc
hashb769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501
hashae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae
hash112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf
hash9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611
hash1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c
hash0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3
hash66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb
hash61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc
hash19fbbf9cb32662f86b6ab00e59f7490d
hashd064fd7665977adfe76a48d733460a03
hashe24f150e02fba6d0cbbcfbf21b1347e5
hash7e43538699f2610780b9d060937be36c08f3b257
hashd1a773b1cc3a3f756337ffb9c6d8cd6c13d2a14d
hashddcfd1cbfd231c3b75d8a8b41fae379f0eebf4eb
hash232939a64c11f6535ace11e260d5f811
hash732ba148707ddb33200ca90e64f3d078
hashd747f766bc64667e68c51085995dc988
hash1f36410ec83e0a613de517bcb358f98c9ea54ca2
hash327687610688216c928ba14e3cd54dec9371b292
hash4a9cc9e7aa2a746a033c83304faa25f3c4569b9f

Threat ID: 6aa23b04acd9273b49952e81

Added to database: 09/10/2026, 05:07:16 UTC

Last enriched: 09/10/2026, 05:23:46 UTC

Last updated: 09/11/2026, 15:00:04 UTC

Views: 28

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses