Gigabud exploits Android cloning to bypass fraud checks
Cybercriminals behind the Gigabud Android banking trojan are using a weaponised app-cloning tool to isolate fraudulent banking activity from malware alerts, according to research published by Group-IB on September 9. The cybersecurity company said Gigabud is being paired with Vwork, a modified fork of the open-source Android application Shelter, to create a separate Work Profile and place banking…
Gigabud, a Chinese-language Android banking trojan, is being used by the GoldFactory cybercrime group to bypass fraud detection systems, according to Group-IB research published on September 9. The group has weaponized an app-cloning tool called Vwork, a modified version of the open-source Android application Shelter, to create a separate Work Profile for banking applications.
This technique allows Gigabud to remain undetected by security checks within the cloned banking application placed in the work profile. The technique involves isolating fraudulent banking activity from malware alerts by placing banking applications in the work profile, which appears as a different or previously unseen environment to the fraud monitoring system.
This makes it difficult for banks to connect earlier malware detection with a later transaction from the same device, complicating device-risk assessments and fraud monitoring.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.