Interestana
Home/News/Gigabud Trojan Hides Banking Apps in Android Work Profiles
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Gigabud Trojan Hides Banking Apps in Android Work Profiles

Gigabud Trojan Hides Banking Apps in Android Work Profiles

The Gigabud banking trojan has evolved its evasion tactics by creating a secondary Android application that establishes a work profile on an infected device, subsequently installing a modified banking application within this isolated environment. Security firm Group-IB detailed this new modus operandi in a report published on September 9. Android's work profile feature is typically designated for enterprise applications, creating a distinct partition on the device that separates work-related data and applications from personal ones. This separation is designed to enhance security and privacy for both individuals and organizations. By leveraging this built-in Android functionality, Gigabud aims to circumvent detection mechanisms employed by legitimate banking applications, which often include checks to identify the presence of malware or unauthorized software that could compromise user accounts. The trojan's strategy involves first compromising a device and then deploying its malicious payload, which includes the creation of the work profile and the installation of the tampered banking app. This tampered app likely mimics a legitimate banking application, prompting users to enter their credentials, which are then exfiltrated by the attackers. Group-IB's analysis indicates that this method allows Gigabud to operate with a lower risk of being detected by security software or the banking apps themselves, as the malicious application resides in a segregated space that standard security scans might overlook. The report does not specify the exact number of infections or the geographic regions most affected by this particular variant of Gigabud. However, the sophistication of this new technique highlights the ongoing cat-and-mouse game between malware developers and cybersecurity researchers. The implications of this development are significant for mobile banking security, as it suggests that even applications designed with security in mind may be vulnerable to sophisticated evasion techniques. Users are advised to maintain vigilance regarding app permissions, download applications only from trusted sources like the Google Play Store, and ensure their devices are running the latest security patches. The use of Android's work profile feature by malware represents a novel approach to hiding malicious activities, moving beyond traditional methods of obfuscation or root access exploitation. This tactic could potentially be adopted by other malware families targeting mobile banking users. Group-IB's research team continuously monitors emerging threats and provides intelligence to aid in the development of more robust security solutions for mobile platforms. The firm's findings are typically based on forensic analysis of infected devices and network traffic associated with malware command-and-control infrastructure. Further investigation into the specific vulnerabilities exploited by Gigabud to gain initial access and install its components is ongoing, as is the development of countermeasures to detect and neutralize this evolving threat.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next