logo

Android malware creates a hidden copy of your banking app

ID: c63da6e8-c4e3-5c0b-9552-01d968261c5a

STIX ID: report--c63da6e8-c4e3-5c0b-9552-01d968261c5a

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-09-11

Date Updated: 2026-09-12

...
...

The report details Gigabud, an Android banking Trojan that sideloads via fake apps and uses a malicious Shelter fork (Vwork) to create a work profile, clone targeted banking apps, and execute fraudulent transactions from the cloned profile — potentially evading anti-fraud and in-app malware detection. It describes infection mechanics (phishing, permission abuse, overlays), indicators detected by Malwarebytes, and mitigation advice (avoid sideloading, revoke permissions, use up-to-date mobile security, contact banks).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.