Description

GoldFactory has enhanced its Gigabud Android banking trojan with Vwork, a weaponized fork of the open-source Shelter application. The technique abuses Android Work Profile functionality to create an isolated environment where targeted banking applications can be cloned and operated, helping attackers separate fraudulent activity from malware activity visible in the device’s primary profile. Gigabud is an Android Remote Access Trojan active since 2022 and associated with GoldFactory. Attackers typically distribute it through phishing websites, messaging platforms, social-media lures, and fraudulent applications impersonating banks, government agencies, airlines, or other trusted services. After installation, the malware requests high-risk permissions such as Accessibility access, overlay privileges, and battery-optimization exemptions. Accessibility access can allow attackers to observe screen content, automate gestures, capture credentials, and remotely control the device. Vwork extends this capability by modifying Shelter’s Work Profile architecture. Gigabud can instruct Vwork to provision a profile, clone selected applications, enumerate cloned packages, and launch them within the isolated environment. The malware communicates with Vwork using functions including initVwa, cloneApp, and uploadCloneApps, while cloned applications are identified using the vwa- prefix in C2 traffic. This separation can weaken conventional security telemetry because suspicious activity in the personal profile may be disconnected from fraudulent transactions performed through the cloned banking application.