Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

Summary

The Gigabud banking trojan has evolved its tactics by creating a hidden work profile on infected Android devices. This work profile is used to install a tampered banking app, bypassing malware checks.

IFF Assessment

FOE

This new technique employed by the Gigabud banking trojan allows it to evade detection mechanisms, posing a greater threat to users and financial institutions.

Defender Context

Defenders should be aware of this evolving tactic where malware leverages Android's work profile feature to hide malicious applications. This necessitates enhanced detection capabilities that can inspect the contents of work profiles, even when they are intended to be isolated.

Read Full Story →