Gigabud Banking Trojan Uses Android Work Profiles to Evade Malware Checks
What Happened — The Gigabud banking trojan now drops a second Android app that creates a work profile on the infected device and installs a tampered banking application inside that isolated container, according to a Group‑IB report (Sept 9 2026). The work‑profile trick lets the malware bypass many mobile‑security checks that only scan the personal profile.
Why It Matters for Trust & Control Assurance
- This technique exploits a gap in Mobile Device Management (MDM) policies: without continuous verification that work‑profile apps are vetted, an organization cannot prove it enforces a defensible “approved‑app” control.
- Continuous control‑assurance programs that collect evidence of profile configuration and app signing can detect such hidden payloads before they reach end‑users.
- Mapping the “application isolation” control to a single VCF objective (e.g., Secure Configuration & Isolation of Mobile Apps) satisfies audit requirements across NIST CSF 2.0, ISO 27001 and other frameworks simultaneously.
Who Is Affected – Financial services firms, mobile‑banking providers, and any enterprise that permits Android work profiles on employee devices (FIN_SERV, MSP, CLOUD_HOST).
Recommended Actions
- Review and tighten MDM policies to require signed, whitelisted apps in both personal and work profiles.
- Deploy continuous monitoring that records profile creation events and validates app signatures against a trusted inventory.
- Conduct a rapid audit of existing work‑profile deployments and remediate any unauthorized apps.
Source: The Hacker News
Technical Notes
- Attack vector: Malware that leverages Android’s native work‑profile feature to hide a tampered banking app.
- No public CVE; the technique exploits Android’s built‑in isolation rather than a software flaw.
- Data at risk: Banking credentials, transaction authorisation tokens, and personal financial information.
Source: Group‑IB report, Sept 9 2026