Android malware creates a hidden copy of your banking app
ID: c63da6e8-c4e3-5c0b-9552-01d968261c5a
STIX ID: report--c63da6e8-c4e3-5c0b-9552-01d968261c5a
Feed Name: Malwarebytes Blog
The report details Gigabud, an Android banking Trojan that sideloads via fake apps and uses a malicious Shelter fork (Vwork) to create a work profile, clone targeted banking apps, and execute fraudulent transactions from the cloned profile — potentially evading anti-fraud and in-app malware detection. It describes infection mechanics (phishing, permission abuse, overlays), indicators detected by Malwarebytes, and mitigation advice (avoid sideloading, revoke permissions, use up-to-date mobile security, contact banks).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
