Gigabud / Vwork: Account Takeover via Android Banking App Cloning in Work Profiles
1. Basic Information Original Title: Indonesia Hit by Android Banking App Cloning Campaign Source: Dark Reading, Group-IB Publication Date: 2026-09-11 Severity: High Basis for Severity: Actual financial losses and numerous compromised devices have been confirmed, and the enterprise Work Profile feature is being abused to isolate and evade detection in consumer banking fraud. Original Link:…
On September 11, 2026, Dark Reading and Group-IB reported that Indonesian users are facing a serious threat from a campaign cloning Android banking apps. This attack, traced back to the GoldFactory threat group, utilizes a combination of Android accessibility permissions and Work Profiles to clone banking apps and take control of compromised devices.
The attack begins when a victim sideloads what appears to be a legitimate app, such as an airline or government app. The malicious APK, disguised as the legitimate one, gains accessibility permissions, allowing it to display over other apps and ignore battery optimizations. Once installed, the attacker obtains the device owner's credentials through a fake banking login screen and records screen lock codes via an alternative method.
After obtaining the necessary permissions, the attacker deploys Vwork, an Android banking Trojan, and creates an Android Work Profile within the compromised device. Vwork then clones the banking app into the newly created Work Profile, effectively isolating the fraudulent app from the user's personal profile. By cloning the banking app, the attacker gains control over the device's screen, allowing them to perform unauthorized transactions without the user's knowledge.
The success of this attack hinges on the user's willingness to sideload malicious apps and grant the required permissions. If these conditions are met, the attacker can successfully clone banking apps, gain remote control of the device, and make unauthorized fund transfers. This type of attack could potentially be adapted to target other banking and payment apps, posing a significant risk to users worldwide.
To detect this attack, users should be vigilant for unexpected permission prompts, such as those for accessibility and display over other apps. They should also be cautious of suspicious apps with unusual icons, such as a briefcase, and any abnormal banking activity. Administrators and security professionals should monitor for APK installations from unofficial sources, net.yy.vwork, and rapid Work Profile creations.
Additionally, they should keep an eye out for any unusual device registrations and transfer patterns linked to the affected bank accounts.
To mitigate the risk of this attack, users should avoid sideloading apps from external sites and only install apps from trusted sources. Device administrators can restrict APK installations and unauthorized app permissions through device policies. Banks can enhance security by linking new device registrations and transfer activities in mobile banking apps, requiring additional authentication when necessary.
By staying informed and implementing appropriate security measures, users and organizations can better protect themselves against this and similar threats.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.