HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Gigabud Banking Trojan Uses Android Work Profiles to Evade Malware Checks

Gigabud now installs a second Android app that creates a work profile and drops a tampered banking app inside it, allowing the malware to slip past many mobile‑security scans. This highlights the need for continuous verification of work‑profile configurations as part of audit‑ready control assurance.

LiveThreat™ Intelligence · 📅 September 10, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
1 recommended
📰
Source
thehackernews.com

Gigabud Banking Trojan Uses Android Work Profiles to Evade Malware Checks

What Happened — The Gigabud banking trojan now drops a second Android app that creates a work profile on the infected device and installs a tampered banking application inside that isolated container, according to a Group‑IB report (Sept 9 2026). The work‑profile trick lets the malware bypass many mobile‑security checks that only scan the personal profile.

Why It Matters for Trust & Control Assurance

  • This technique exploits a gap in Mobile Device Management (MDM) policies: without continuous verification that work‑profile apps are vetted, an organization cannot prove it enforces a defensible “approved‑app” control.
  • Continuous control‑assurance programs that collect evidence of profile configuration and app signing can detect such hidden payloads before they reach end‑users.
  • Mapping the “application isolation” control to a single VCF objective (e.g., Secure Configuration & Isolation of Mobile Apps) satisfies audit requirements across NIST CSF 2.0, ISO 27001 and other frameworks simultaneously.

Who Is Affected – Financial services firms, mobile‑banking providers, and any enterprise that permits Android work profiles on employee devices (FIN_SERV, MSP, CLOUD_HOST).

Recommended Actions

  • Review and tighten MDM policies to require signed, whitelisted apps in both personal and work profiles.
  • Deploy continuous monitoring that records profile creation events and validates app signatures against a trusted inventory.
  • Conduct a rapid audit of existing work‑profile deployments and remediate any unauthorized apps.

Source: The Hacker News

Technical Notes

  • Attack vector: Malware that leverages Android’s native work‑profile feature to hide a tampered banking app.
  • No public CVE; the technique exploits Android’s built‑in isolation rather than a software flaw.
  • Data at risk: Banking credentials, transaction authorisation tokens, and personal financial information.

Source: Group‑IB report, Sept 9 2026

📰 Original Source
https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →