[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPeJBTo1uvkNddblL-0r52qCPtqFMqtYqSlWV8U-miVY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"cf113c74-dee3-40f5-95a8-142a314e6fa8","gigabud-trojan-exploits-android-work-profiles-to-evade-banking-app-security","94f87024-6e0c-4ac2-9466-ffe91650caae","Gigabud Trojan Exploits Android Work Profiles to Evade Banking App Security","The Gigabud banking trojan leverages Android's legitimate work profile feature as a hiding mechanism, creating an isolated environment where a tampered banking app can operate outside the reach of standard security scans. This represents a sophisticated abuse of a trusted OS feature, demonstrating how attackers increasingly weaponize built-in platform capabilities rather than relying solely on traditional exploitation techniques. The attack chain — confirmed on real infected devices in Indonesia — allows credential theft and fraudulent transactions to proceed undetected. This matters because it highlights a critical gap: mobile security tools that rely on surface-level app scanning can be completely bypassed when malware manipulates the device's own profile architecture. Users and organizations that lack mobile threat defense (MTD) solutions or device management policies are particularly exposed.","**Immediate actions:**\n- Deploy a Mobile Threat Defense (MTD) solution capable of detecting behavioral anomalies and suspicious work profile creation events.\n- Enforce Mobile Device Management (MDM) policies that restrict or alert on unauthorized work profile provisioning on personal and corporate devices.\n- Educate end users to avoid sideloading apps and to report unexpected prompts to enable device management or work profiles.\n\n**Long-term improvements:**\n- Implement Zero Trust principles for mobile access, requiring continuous device health attestation before allowing access to banking or sensitive applications.\n- Establish a formal mobile application vetting process to ensure only approved, verified apps are used for financial transactions.\n- Regularly audit enrolled device configurations to detect policy drift or unauthorized profile changes.\n\n**Detection measures:**\n- Monitor device logs and MDM telemetry for anomalous work profile creation events associated with unknown provisioning sources.\n- Integrate mobile threat intelligence feeds (e.g., Group-IB, threat sharing platforms) to stay current on evolving Android malware tactics.\n- Set up alerts for banking app integrity failures or unexpected re-installations within isolated profiles.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 10 – Malware Defenses","CIS Control 14 – Security Awareness and Skills Training","NIST SP 800-124 Rev. 2 – Guidelines for Managing the Security of Mobile Devices","NIST AC-2 – Account Management","NIST SI-3 – Malicious Code Protection","NIST DE.CM-4 – Malicious Code Detection","GDPR Article 32 – Security of Processing (for organizations handling EU user banking data)","OWASP Mobile Top 10 – M8: Code Tampering","OWASP Mobile Top 10 – M10: Extraneous Functionality","published","2026-09-10T14:21:55.777802+00:00","2026-09-10T14:21:55.485+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fgigabud-creates-android-work-profiles.html","gigabud-creates-android-work-profiles-to-hide-from-banking-app-malware-checks-4cb585","Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]