Gigabud Banking Malware Hides Inside Android Work Profiles to Dodge Security Checks
A new version of the Gigabud trojan sets up a separate Android work profile and installs a fake banking app inside it, keeping the malicious activity hidden from the phone's normal security scans.

Key points
- Group-IB published a report on September 9 detailing a new Gigabud Android banking trojan variant that abuses work profiles to hide a tampered banking app.
- The malware installs a second dropper app that creates the work profile, isolating the fake bank app from Android's usual security checks in the personal space.
- Victims are lured through fake job offers, dating scams and phishing sites impersonating banks and government services, chiefly across Southeast Asia.
- The fake banking app inside the work profile steals login details, one-time passcodes and card data, then relays them to the criminals.
- Users should install banking apps only from official stores and be wary of any app that asks to set up a "work" or "managed" profile.
A banking trojan called Gigabud, which is malicious software designed to steal money from mobile banking customers, has learned a new trick. It hides inside the part of an Android phone normally reserved for employer software.
Security firm Group-IB described the technique in a report published on September 9. The finding was also covered by The Hacker News.
What is Gigabud actually doing?
The malware installs a second app on the phone. That second app then creates an Android work profile, a separate walled-off area that Android usually keeps for company-issued software, and drops a tampered banking app inside it.
Anything inside the work profile is sealed off from apps in the personal space. That means the security tools most people rely on, including Google Play Protect scans and the bank's own anti-fraud checks running in the main profile, cannot easily see what the fake banking app is doing.
Once inside, the tampered app behaves like the real bank. It asks for the username, password, one-time passcode and card details. Those credentials are sent straight to the criminals running the campaign.
How do people end up with it on their phone?
Victims are tricked into installing the first-stage app themselves. Group-IB says the lures include fake job adverts, romance scams on dating apps, and phishing pages, which are fake websites built to look like the real thing, dressed up as banks, tax offices and government portals.
Most of the targeting so far has been in Southeast Asia, with Thailand, Indonesia, Vietnam and the Philippines named in the research. The apps are sideloaded, meaning they are installed from a link or file rather than from the Google Play Store.
Why does the work profile trick matter?
Android work profiles exist for a good reason. They let a company put its email and business apps on an employee's personal phone without mixing the two.
The criminals have turned that same isolation against the user. Fraud detection features baked into legitimate banking apps often check the environment they are running in. If a suspicious app is running alongside them, they can refuse to open or flag the session.
Put the malicious app in a separate profile and those checks come up clean. The user sees a normal-looking bank login and hands over their details.
What should ordinary phone users do?
Stick to the Google Play Store for banking apps, and be very suspicious of any download link sent by email, text or a stranger on a dating app. If a job "recruiter" asks you to install a specific app to receive payments or take a skills test, stop.
Check the phone's settings for any work profile or "managed" account you did not set up yourself. On most Android phones this appears under Settings, then Accounts or Users. If one is there and you did not add it, remove it and run a scan.
Banks in the affected regions will likely need to update their fraud models. The old assumption that a scan of the personal profile is enough no longer holds.



