Skip to content
Residential technology help and small-business ITOwner-led. Clearly scoped. Salem County based. 609-202-2208
Cyber News

Gigabud can clone a banking app in an Android work profile

Malwarebytes says the Gigabud banking Trojan can create a separate Android work profile and place a copy of a banking app inside it. Users who installed suspicious apps should check for duplicate apps and unusual permissions.

Published September 11, 2026 Updated September 11, 2026 6 min read
Gigabud can clone a banking app in an Android work profile

Malwarebytes says the Gigabud banking Trojan can create a separate Android work profile and place a copy of a banking app inside it. Users who installed suspicious apps should check for duplicate apps and unusual permissions.

In 60 seconds

  • Android users who installed suspicious airline, tax, or government apps should check recent installs and special permissions.
  • A duplicate banking app in a work profile is suspicious, but a work profile alone does not prove infection.
  • If a suspicious app had Accessibility access, contact your bank through a trusted channel.
  • Do not install unsolicited app files or approve unusual requests to control the phone or cover other apps.

Who should care and what to do today

This report is particularly relevant to Android users who installed a suspicious or fake airline, tax, or government app from a message, social media post, or website. Malwarebytes says the Gigabud banking Trojan can create a separate work profile, copy a banking app into it, and use that copy for fraudulent transactions.

Check recent app installs for anything you do not recognize. Look for a banking app that appears more than once, an unfamiliar work profile, or requests for Accessibility access or permission to display over other apps. A work profile is a separate area on Android that normally keeps work apps and data apart from personal apps. Its presence alone does not prove a problem.

If you installed a suspicious app and gave it Accessibility access, stop using that phone for banking and contact your bank through a trusted phone number, website, or known-good device. Then review and remove the app’s special permissions and uninstall it. Malwarebytes says a factory reset may be worth considering after preserving only known-good data.

How Gigabud creates the second banking app

According to Malwarebytes, victims are lured into installing fake airline, tax, or government apps through phishing sites, messages, or social media. An Android app installation file is often called an APK. Installing an APK from outside the official app store is known as sideloading.

The fake app may ask for Accessibility access and permission to display over other apps. Accessibility access can let an app interact with parts of the phone on a user’s behalf. An overlay is a screen placed over another app. Malwarebytes says these features can help steal banking passwords and the phone’s PIN.

The malware then installs Vwork, a modified version of the legitimate open-source Shelter tool. Shelter can create a work profile and run a second copy of an app for legitimate reasons. Malwarebytes says Vwork changes those functions so Gigabud’s operator can create a profile, clone a selected banking app, and control the setup remotely. Vwork can also hide its launcher icon.

Malwarebytes says the operator may carry out transactions from the new profile, sometimes with a black screen covering activity. Because Android keeps profiles separate, security tools or bank systems that do not connect activity across profiles may have a harder time linking the transaction with malware found in the personal profile.

What to check, and what not to assume

Use your phone’s Settings search to look for “Accessibility,” “display over other apps,” and “work profile.” Menu names differ between Android phone makers. Review recent app installs and look for duplicate banking apps or an app that does not match something you intentionally downloaded.

A permission request by itself is not proof of infection. Some legitimate apps use special access. The concern is the combination of an unexpected installation, powerful permissions, and a cloned banking app. Malwarebytes specifically says that a cloned banking app merits scrutiny.

Do not approve Accessibility or display-over-other-apps requests for an unsolicited airline, tax, delivery, or government app. Do not treat every work profile as malware, and do not delete a legitimate work profile without checking whether it contains work data. For future installations, use the official app store or a direct link from the publisher’s known website.

What to do if the signs are present

If you find a suspicious app with powerful permissions or a cloned banking app, avoid entering banking details on that phone. Contact the bank through a trusted channel and explain that the phone may have been compromised. Use a known-good device if possible.

After speaking with the bank, revoke the suspicious app’s Accessibility and display-over-other-apps permissions, then uninstall it. If you cannot be confident that the phone is clean, Malwarebytes says to consider a factory reset after preserving only data you know is safe. A separate work profile can have legitimate uses, so do not remove one simply because it exists.

Does this affect me?

Who may be affected
Android users who installed a suspicious or fake airline, tax, or government app from a message, social media post, or website. People who find a cloned banking app or granted unusual special permissions should take extra care.
How to check
Review recent app installs, duplicate banking apps, work profiles, Accessibility access, and permission to display over other apps. A work profile alone is not proof of compromise.
What to do
If a suspicious app had Accessibility access, contact your bank through a trusted channel before using that phone for banking.
What to avoid
Do not install unsolicited Android app files, approve unusual Accessibility or overlay requests, or enter banking details on a phone you suspect is compromised.

Common questions

Is every Android work profile dangerous?

No. Android work profiles can legitimately separate work apps and data from personal apps. Malwarebytes says the more suspicious sign is a cloned banking app inside a separate profile, especially after an unexpected app installation or unusual permission request.

What if I installed a suspicious app but do not see a duplicate banking app?

If the app had Accessibility access or other powerful permissions, contact your bank through a trusted channel and avoid banking on that phone until you get advice. Review and remove the permissions, uninstall the app, and consider a factory reset after preserving only known-good data.

What does sideloading mean?

Sideloading means installing an Android app from outside the official app store, usually with an APK, which is an Android app installation file. Malwarebytes advises using the official store or a direct link from the publisher’s website instead.

Does a second banking app prove that Gigabud is on my phone?

No. Malwarebytes says a cloned banking app is definitely suspicious, but the article does not say that every duplicate proves Gigabud infection. Consider the app’s source, recent permissions, and other signs, and contact your bank through a trusted channel if needed.

Primary source

This article is based on Malwarebytes, “Android malware creates a hidden copy of your banking app,” published September 11, 2026: https://www.malwarebytes.com/blog/mobile/2026/09/android-malware-creates-a-hidden-copy-of-your-banking-app Read the complete original source.

Get the important updates without the noise

Choose the devices and topics you care about in Cyber Alerts.

Choose my alerts

Article history: Published Sep 11, 2026 at 8:49 am EDT. Updates and corrections are noted here when material facts change.