Android Work Profile abuse can create detection gaps by separating banking malware from the profile where fraudulent application activity occurs.
The campaign combines Gigabud with Vwork to clone or place banking apps inside a separate work profile while attackers remotely conduct transactions.
Enterprise teams should verify enrollment, restrict unnecessary sideloading, scrutinize sensitive permissions, and correlate mobile findings with identity and application evidence.
Hexnode UEM supports Android defenses through unknown-source restrictions, app Blocklist/Allowlist controls, and Compliance Policy, but coverage depends on enrollment mode and policy scope.
Android Work Profile abuse is helping banking malware operators hide fraudulent activity on infected phones in Indonesia. The campaign combines Gigabud, a remote access banking trojan, with Vwork, a companion app that places banking applications inside a separate work profile.
Group-IB observed approximately 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026. Estimated losses reached roughly $961,000. These figures describe observed activity, rather than the campaign’s full regional impact.
For enterprise IT teams, the incident raises a practical question: does your security assessment cover the environment where an application actually runs?
How Android Work Profile abuse enables banking fraud
The attack starts with social engineering. Victims install fake applications outside official stores, often after encountering services impersonating airlines, tax authorities, or government portals. Gigabud then requests Accessibility permissions, which enable extensive interaction with the phone.
The malware can inventory installed applications, overlay fake login screens, capture credentials and lock-screen codes, and give operators remote control. Attackers use that access to introduce Vwork and move targeted banking activity into another profile.
From device control to profile isolation
Vwork derives from Shelter, an open-source application that uses Android Work Profile to isolate apps.After gaining Accessibility access, Gigabud programmatically drives the Vwork app UI to set up a Work Profile without manual user interaction. Vwork exposes profile-management functions that Gigabud invokes remotely over its command channel.
Operators clone a banking application into the work profile or introduce a tampered app, then conduct fraudulent transactions while a black screen conceals activity from the victim.
Profile isolation creates the visibility gap: security tools running inside the Work Profile cannot inspect memory or running processes in the Personal Profile (and vice versa). Consequently, security checks inside the cloned banking app fail to observe Gigabud operating in the personal profile.
What enterprise security teams should learn
The enterprise lesson concerns how organizations establish device trust. A familiar interface or work-profile badge should never substitute for verified enrollment and an understood management scope.
Treat the following as priorities when reviewing mobile access:
Verify enrollment and management scope: Distinguish BYOD Profile Owner enrollment, company-owned work-profile enrollment, and fully managed Device Owner enrollment. BYOD management primarily covers the work container. Company-owned work profiles support additional controls while preserving personal-profile privacy. For broader device-wide restrictions, evaluate fully managed Device Owner enrollment and verify support for the required sideloading and Accessibility-service controls.
Examine permission requests: Teach employees to report unexpected Accessibility requests, overlays, and unfamiliar profile-setup prompts.
Coordinate investigations: Review mobile findings alongside identity and application logs when investigating suspected account misuse.
These recommendations extend the campaign’s lessons to enterprise environments. The cited research documents banking fraud; it does not establish that these operators compromised corporate applications or bypassed enterprise conditional access.
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
Hexnode UEM gives administrators documented controls for application restrictions and compliance evaluation. Their effectiveness depends on Android version, enrollment mode, and policy scope.
Reduce exposure to Android Work Profile abuse
Start with three controls that address installation risks and configuration gaps:
Security priority
Hexnode UEM capability
Practical application
Reduce sideloading
Install apps from unknown sources restriction
Disable the setting on supported managed devices to restrict unapproved installation paths.
Control accessible apps
App Management (Blocklist/Allowlist)
Define permitted or prohibited applications. In BYOD setups enrolled in Profile Owner mode, these restrictions apply exclusively to apps inside the work container.
Identify policy violations
Compliance Policy
Evaluate Blocklisted Apps Count, Missing Apps Count, Password Compliance, Rooted Status, and Device Encryption against configured requirements.
Scope matters especially for BYOD. In Android Enterprise profile owner mode, Hexnode’s app blocklisting and allowlisting apply only to work apps. Administrators should account for that boundary when assessing personal-profile exposure. Compliance results also describe configured checks; they do not prove that a device contains no malware.
FAQs
How can malware abuse Android Work Profiles?
Malware can abuse Work Profile functionality to place or clone applications inside a separate profile and conduct activity there. In the documented Gigabud campaign, Vwork enabled operators to move targeted banking activity into a work profile while Gigabud operated from the personal profile.
Can Android Work Profile isolation make malware harder to detect?
Yes. Profile separation can limit what security checks in one profile can observe about activity occurring in another. In this campaign, that separation made it harder to connect malware detected in the personal profile with fraudulent banking activity inside the work profile.
Does an Android Work Profile mean a device is trusted or secure?
No. A Work Profile provides separation between applications and data, but its presence alone does not establish device trust. Enterprises should verify approved enrollment, management scope, application sources and relevant security policies. To strengthen device trust, organizations should combine profile separation with Hexnode UEM compliance policies, conditional access checks, and sideloading restrictions appropriate to the enrollment mode.
Keep profile separation within a broader security strategy
Android Work Profiles remain useful for separating business and personal applications. This campaign demonstrates why organizations must also examine enrollment, installation permissions, application trust, and the limits of security visibility.
Review these controls together, define who investigates suspicious mobile activity, and establish when identity administrators should restrict access. Evaluate Hexnode UEM against your actual Android enrollment modes and BYOD requirements to build a practical, repeatable mobile security baseline.
Strengthen Android Work Profile Security
Control app access, enforce compliance, and reduce Android security risks with Hexnode UEM.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.