Indonesia has been hit by a new Android banking fraud campaign in which cybercriminals are using malware to clone banking applications and hide fraudulent activity from security checks. Security researchers from Group-IB found that the campaign involves the Gigabud Android banking trojan and another malicious application called Vwork. The attackers use Vwork to create a separate Android work profile and place a cloned banking application inside it. The technique has been confirmed on infected devices in Indonesia and is designed to make fraudulent transactions harder for banking security systems to detect.
The attack starts when victims are tricked into installing fake applications through phishing websites, messaging platforms or social media. These applications can pretend to be airline services, tax authorities or government services instead of looking like obvious malware. After installation, Gigabud asks for Accessibility access, permission to appear over other applications and an exemption from battery-saving restrictions. Once Accessibility access is granted, attackers can remotely control important parts of the phone and identify which banking applications are installed on the device.
Gigabud can also steal banking information by placing fake login screens over legitimate banking applications. These screens can capture information entered by the victim, while another hidden overlay can capture the device’s lock-screen code. The attackers can then use the stolen access and remote-control capabilities to perform actions on the victim’s phone. Group-IB found that Vwork is installed shortly after Gigabud in the observed Indonesian infection chain. Vwork creates an isolated Android work profile where a targeted banking application can be cloned.
The use of a separate work profile is important because Android normally keeps applications in different profiles separated from one another. Group-IB said this separation can prevent security checks running in the work profile from seeing malware located in the personal profile. In one confirmed Indonesian case, the application placed inside the work profile was a fake version of a real Indonesian bank’s application. During the fraud process, attackers can operate the device remotely while a black screen hides what is happening from the victim, helping them carry out unauthorized transactions.
The scale of the activity in Indonesia is significant, although Group-IB stressed that its figures represent activity observed by its researchers and do not show the full impact across the country. Between February and July 2026, researchers observed about 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia. The estimated losses from the activity were around $960,939. Gigabud samples designed to work with Vwork have also been found targeting countries including Brazil, Colombia, Egypt, Laos, Mexico, Morocco, the Philippines, Thailand and Türkiye, but the complete Gigabud-Vwork infection chain has so far been confirmed on devices in Indonesia.
Security researchers recommend that Android users install applications only from official app stores and avoid APK files received through suspicious links, messages or social-media posts. Users should also be careful when an unfamiliar application requests Accessibility access, especially when that permission is not necessary for its stated purpose. Group-IB has advised banks to watch for unusual work profiles, duplicate banking applications across profiles and suspicious Accessibility permissions. The discovery shows how attackers are increasingly abusing legitimate Android features, such as work profiles, to separate fraudulent activity from malware and make banking attacks more difficult to detect.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news