importantSYS.SOURCE: The Hacker News• 2026-09-10T17:03:43+05:30
Gigabud Banking Trojan Exploits Android Work Profiles to Bypass Malware Detection
Gigabud, a banking trojan, leverages Android work profiles to hide from malware checks by isolating malicious activities within a separate workspace. The technique, involving a secondary app called Vwork, allows attackers to bypass security measures and conduct fraudulent transactions undetected.
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.
A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That
*** END OF TRANSMISSION ***