Lily
Anne

Android Work Profiles Become a Banking Malware Hideout

Lily Anne

Sep 18, 2026

5 min read

Android Work Profiles Become a Banking Malware Hideout

TL; DR

Android Work Profile abuse can create detection gaps by separating banking malware from the profile where fraudulent application activity occurs.

  • The campaign combines Gigabud with Vwork to clone or place banking apps inside a separate work profile while attackers remotely conduct transactions.
  • Enterprise teams should verify enrollment, restrict unnecessary sideloading, scrutinize sensitive permissions, and correlate mobile findings with identity and application evidence.
  • Hexnode UEM supports Android defenses through unknown-source restrictions, app Blocklist/Allowlist controls, and Compliance Policy, but coverage depends on enrollment mode and policy scope.

Android Work Profile abuse is helping banking malware operators hide fraudulent activity on infected phones in Indonesia. The campaign combines Gigabud, a remote access banking trojan, with Vwork, a companion app that places banking applications inside a separate work profile.

Group-IB observed approximately 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026. Estimated losses reached roughly $961,000. These figures describe observed activity, rather than the campaign’s full regional impact.

For enterprise IT teams, the incident raises a practical question: does your security assessment cover the environment where an application actually runs?

Strengthen Endpoint Security with Hexnode UEM

How Android Work Profile abuse enables banking fraud

The attack starts with social engineering. Victims install fake applications outside official stores, often after encountering services impersonating airlines, tax authorities, or government portals. Gigabud then requests Accessibility permissions, which enable extensive interaction with the phone.

The malware can inventory installed applications, overlay fake login screens, capture credentials and lock-screen codes, and give operators remote control. Attackers use that access to introduce Vwork and move targeted banking activity into another profile.

From device control to profile isolation

Vwork derives from Shelter, an open-source application that uses Android Work Profile to isolate apps.After gaining Accessibility access, Gigabud programmatically drives the Vwork app UI to set up a Work Profile without manual user interaction. Vwork exposes profile-management functions that Gigabud invokes remotely over its command channel.

Operators clone a banking application into the work profile or introduce a tampered app, then conduct fraudulent transactions while a black screen conceals activity from the victim.

Profile isolation creates the visibility gap: security tools running inside the Work Profile cannot inspect memory or running processes in the Personal Profile (and vice versa). Consequently, security checks inside the cloned banking app fail to observe Gigabud operating in the personal profile.

What enterprise security teams should learn

The enterprise lesson concerns how organizations establish device trust. A familiar interface or work-profile badge should never substitute for verified enrollment and an understood management scope.

Treat the following as priorities when reviewing mobile access:

  • Verify enrollment and management scope: Distinguish BYOD Profile Owner enrollment, company-owned work-profile enrollment, and fully managed Device Owner enrollment. BYOD management primarily covers the work container. Company-owned work profiles support additional controls while preserving personal-profile privacy. For broader device-wide restrictions, evaluate fully managed Device Owner enrollment and verify support for the required sideloading and Accessibility-service controls.
  • Review installation paths: Minimize unnecessary APK installation and document legitimate exceptions.
  • Examine permission requests: Teach employees to report unexpected Accessibility requests, overlays, and unfamiliar profile-setup prompts.
  • Coordinate investigations: Review mobile findings alongside identity and application logs when investigating suspected account misuse.

These recommendations extend the campaign’s lessons to enterprise environments. The cited research documents banking fraud; it does not establish that these operators compromised corporate applications or bypassed enterprise conditional access.

cybersecurity-kit

Cybersecurity kit

Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.

Download the Resource Kit

How Hexnode UEM supports Android defenses

Hexnode UEM gives administrators documented controls for application restrictions and compliance evaluation. Their effectiveness depends on Android version, enrollment mode, and policy scope.

Reduce exposure to Android Work Profile abuse

Start with three controls that address installation risks and configuration gaps:

Security priority Hexnode UEM capability Practical application
Reduce sideloading Install apps from unknown sources restriction Disable the setting on supported managed devices to restrict unapproved installation paths.
Control accessible apps App Management (Blocklist/Allowlist) Define permitted or prohibited applications. In BYOD setups enrolled in Profile Owner mode, these restrictions apply exclusively to apps inside the work container.
Identify policy violations Compliance Policy Evaluate Blocklisted Apps Count, Missing Apps Count, Password Compliance, Rooted Status, and Device Encryption against configured requirements.

Scope matters especially for BYOD. In Android Enterprise profile owner mode, Hexnode’s app blocklisting and allowlisting apply only to work apps. Administrators should account for that boundary when assessing personal-profile exposure. Compliance results also describe configured checks; they do not prove that a device contains no malware.

FAQs

Malware can abuse Work Profile functionality to place or clone applications inside a separate profile and conduct activity there. In the documented Gigabud campaign, Vwork enabled operators to move targeted banking activity into a work profile while Gigabud operated from the personal profile.

Yes. Profile separation can limit what security checks in one profile can observe about activity occurring in another. In this campaign, that separation made it harder to connect malware detected in the personal profile with fraudulent banking activity inside the work profile.

No. A Work Profile provides separation between applications and data, but its presence alone does not establish device trust. Enterprises should verify approved enrollment, management scope, application sources and relevant security policies. To strengthen device trust, organizations should combine profile separation with Hexnode UEM compliance policies, conditional access checks, and sideloading restrictions appropriate to the enrollment mode.

Keep profile separation within a broader security strategy

Android Work Profiles remain useful for separating business and personal applications. This campaign demonstrates why organizations must also examine enrollment, installation permissions, application trust, and the limits of security visibility.

Review these controls together, define who investigates suspicious mobile activity, and establish when identity administrators should restrict access. Evaluate Hexnode UEM against your actual Android enrollment modes and BYOD requirements to build a practical, repeatable mobile security baseline.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.