Gigabud banking trojan now creates Android work profiles to hide tampered banking apps from security checks. Here's how it works and how to stay safe.
### Gigabud's Sneaky New Trick: Work Profiles
You know that work profile on your Android phone? The one that keeps your company email separate from your personal stuff? Well, a banking trojan called Gigabud just figured out how to abuse it. According to a report from security firm Group-IB published on September 9, Gigabud now installs a second app that creates a work profile on an infected device. Inside that profile, it drops a tampered banking app. Why? To slip past the malware checks that legitimate banking apps use to detect tampering.
### What Exactly Is a Work Profile?
Think of a work profile as a phone within your phone. Android created it so your employer can manage work apps without touching your personal photos, messages, or social media. The two spaces are walled off from each other. That isolation is normally a good thing. But Gigabud turns it into a hiding spot. The malware essentially says to the banking app, "Hey, I'm in a clean work environment—nothing suspicious here." And the banking app, trusting that separation, might not run its usual integrity checks. It's like a burglar putting on a security guard's uniform to walk past the front desk.
### Why This Matters for Your Phone
If you use banking apps on Android—and who doesn't?—this is a big deal. Gigabud isn't new. It's been around since 2023, mostly targeting users in Southeast Asia. But this work-profile trick is a fresh escalation. It shows how malware authors are getting creative with Android's own features. They're not breaking down the door anymore; they're using the key you gave them.
> "The work profile is supposed to be a trusted space. Gigabud weaponizes that trust to bypass security checks." — Group-IB researcher
- **The infection chain:** You download a malicious app (often from a third-party store or a phishing link). It quietly installs a second app that creates the work profile.
- **The payload:** Inside the work profile, a fake banking app waits. When you open your real banking app, the malware can overlay fake login screens or steal credentials.
- **The evasion:** Because the fake app lives in a separate profile, many security tools don't see it. Your bank's app might not either.
### How to Protect Yourself
First, stick to the Google Play Store. Gigabud typically spreads through sideloaded apps and shady websites. Second, check your phone for unknown work profiles. Go to Settings > Accounts or Settings > Work profile. If you see a work profile you didn't create, remove it immediately. Third, keep your banking apps updated—they're constantly adding new defenses. And finally, consider using a reputable mobile security app. It won't catch everything, but it's better than flying blind.
### The Bigger Picture
This isn't just about Gigabud. It's a reminder that your phone's built-in security features can be turned against you. Work profiles were designed to protect your data from your employer, not to protect malware from your bank. As long as Android remains the world's most popular mobile OS, criminals will keep finding new ways to abuse its architecture. Stay skeptical. If an app asks for weird permissions or you notice a second version of your banking app you didn't install, don't ignore it. Your money is worth the extra look.
So next time you see that work profile icon, remember: it's not always your boss watching. Sometimes it's someone far worse.