Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
Summary
The Gigabud banking trojan has evolved its tactics by creating a hidden work profile on infected Android devices. This work profile is used to install a tampered banking app, bypassing malware checks.
IFF Assessment
FOE
This new technique employed by the Gigabud banking trojan allows it to evade detection mechanisms, posing a greater threat to users and financial institutions.
Defender Context
Defenders should be aware of this evolving tactic where malware leverages Android's work profile feature to hide malicious applications. This necessitates enhanced detection capabilities that can inspect the contents of work profiles, even when they are intended to be isolated.