{"id":1772,"date":"2026-09-18T13:53:20","date_gmt":"2026-09-18T08:23:20","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1772"},"modified":"2026-09-21T14:42:37","modified_gmt":"2026-09-21T09:12:37","slug":"android-work-profiles-become-a-banking-malware-hideout","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/","title":{"rendered":"Android Work Profiles Become a Banking Malware Hideout"},"content":{"rendered":"<p>Android Work Profile abuse is helping banking malware operators hide fraudulent activity on infected phones in Indonesia. The campaign combines Gigabud, a remote access banking trojan, with Vwork, a companion app that places banking applications inside a separate work profile.<\/p>\n<p>Group-IB observed approximately 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026. Estimated losses reached roughly $961,000. These figures describe observed activity, rather than the campaign\u2019s full regional impact.<\/p>\n<p>For enterprise IT teams, the incident raises a practical question: does your security assessment cover the environment where an application actually runs?<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Endpoint Security with Hexnode UEM<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How Android Work Profile abuse enables banking fraud<\/h2>\n<p>The attack starts with social engineering. Victims install fake applications outside official stores, often after encountering services impersonating airlines, tax authorities, or government portals. Gigabud then requests Accessibility permissions, which enable extensive interaction with the phone.<\/p>\n<p>The malware can inventory installed applications, overlay fake login screens, capture credentials and lock-screen codes, and give operators remote control. Attackers use that access to introduce Vwork and move targeted banking activity into another profile.<\/p>\n<h3>From device control to profile isolation<\/h3>\n<p>Vwork derives from Shelter, an open-source application that uses <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-android-work-profile\/\">Android Work Profile<\/a> to isolate apps.After gaining Accessibility access, Gigabud programmatically drives the Vwork app UI to set up a Work Profile without manual user interaction. Vwork exposes profile-management functions that Gigabud invokes remotely over its command channel.<\/p>\n<p>Operators clone a banking application into the work profile or introduce a tampered app, then conduct fraudulent transactions while a black screen conceals activity from the victim.<\/p>\n<p>Profile isolation creates the visibility gap: security tools running inside the Work Profile cannot inspect memory or running processes in the Personal Profile (and vice versa). Consequently, security checks inside the cloned banking app fail to observe Gigabud operating in the personal profile.<\/p>\n<h2>What enterprise security teams should learn<\/h2>\n<p>The enterprise lesson concerns how organizations establish device trust. A familiar interface or work-profile badge should never substitute for verified enrollment and an understood management scope.<\/p>\n<p>Treat the following as priorities when reviewing mobile access:<\/p>\n<ul>\n<li><strong>Verify enrollment and management scope:<\/strong> Distinguish BYOD Profile Owner enrollment, company-owned work-profile enrollment, and fully managed Device Owner enrollment. BYOD management primarily covers the work container. Company-owned work profiles support additional controls while preserving personal-profile privacy. For broader device-wide restrictions, evaluate fully managed Device Owner enrollment and verify support for the required sideloading and Accessibility-service controls.<\/li>\n<li><strong>Review installation paths:<\/strong> Minimize unnecessary APK installation and document legitimate exceptions.<\/li>\n<li><strong>Examine permission requests:<\/strong> Teach employees to report unexpected Accessibility requests, overlays, and unfamiliar profile-setup prompts.<\/li>\n<li><strong>Coordinate investigations:<\/strong> Review mobile findings alongside identity and application logs when investigating suspected account misuse.<\/li>\n<\/ul>\n<p>These recommendations extend the campaign\u2019s lessons to enterprise environments. The cited research documents banking fraud; it does not establish that these operators compromised corporate applications or bypassed enterprise conditional access.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\r\n \n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode UEM supports Android defenses<\/h2>\n<p>Hexnode UEM gives administrators documented controls for application restrictions and compliance evaluation. Their effectiveness depends on Android version, enrollment mode, and policy scope.<\/p>\n<h3>Reduce exposure to Android Work Profile abuse<\/h3>\n<p>Start with three controls that address installation risks and configuration gaps:<\/p>\n<table style=\"width: 100%; height: 168px;\">\n<thead>\n<tr style=\"height: 24px;\">\n<th style=\"height: 24px;\">Security priority<\/th>\n<th style=\"height: 24px;\">Hexnode UEM capability<\/th>\n<th style=\"height: 24px;\">Practical application<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 48px;\">\n<td style=\"height: 48px;\">Reduce sideloading<\/td>\n<td style=\"height: 48px;\">Install apps from unknown sources restriction<\/td>\n<td style=\"height: 48px;\">Disable the setting on supported managed devices to restrict unapproved installation paths.<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"height: 48px;\">Control accessible apps<\/td>\n<td style=\"height: 48px;\">App Management (Blocklist\/Allowlist)<\/td>\n<td style=\"height: 48px;\">Define permitted or prohibited applications. In BYOD setups enrolled in Profile Owner mode, these restrictions apply exclusively to apps inside the work container.<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"height: 48px;\">Identify policy violations<\/td>\n<td style=\"height: 48px;\">Compliance Policy<\/td>\n<td style=\"height: 48px;\">Evaluate Blocklisted Apps Count, Missing Apps Count, Password Compliance, Rooted Status, and Device Encryption against configured requirements.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Scope matters especially for <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-bring-your-own-device-byod\/\">BYOD<\/a>. In Android Enterprise profile owner mode, Hexnode\u2019s app blocklisting and allowlisting apply only to work apps. Administrators should account for that boundary when assessing personal-profile exposure. <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-compliance-in-cybersecurity\/\">Compliance<\/a> results also describe configured checks; they do not prove that a device contains no malware.<\/p>\n<h3>FAQs<\/h3>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can malware abuse Android Work Profiles?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Malware can abuse Work Profile functionality to place or clone applications inside a separate profile and conduct activity there. In the documented Gigabud campaign, Vwork enabled operators to move targeted banking activity into a work profile while Gigabud operated from the personal profile.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can Android Work Profile isolation make malware harder to detect?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Profile separation can limit what security checks in one profile can observe about activity occurring in another. In this campaign, that separation made it harder to connect malware detected in the personal profile with fraudulent banking activity inside the work profile.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does an Android Work Profile mean a device is trusted or secure?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. A Work Profile provides separation between applications and data, but its presence alone does not establish device trust. Enterprises should verify approved enrollment, management scope, application sources and relevant security policies. To strengthen device trust, organizations should combine profile separation with Hexnode UEM compliance policies, conditional access checks, and sideloading restrictions appropriate to the enrollment mode.<\/p>\n<\/div><\/div><\/div>\n<h3>Keep profile separation within a broader security strategy<\/h3>\n<p>Android Work Profiles remain useful for separating business and personal applications. This campaign demonstrates why organizations must also examine enrollment, installation permissions, application trust, and the limits of security visibility.<\/p>\n<p>Review these controls together, define who investigates suspicious mobile activity, and establish when identity administrators should restrict access. Evaluate Hexnode UEM against your actual Android enrollment modes and BYOD requirements to build a practical, repeatable mobile security baseline.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Android Work Profile Security<\/h5><p>Control app access, enforce compliance, and reduce Android security risks with Hexnode UEM.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Android Work Profile abuse is helping banking malware operators hide fraudulent activity on infected phones&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1789,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,18],"class_list":["post-1772","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-mobile","product_category-unified-endpoint-management","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Android Work Profile Abuse: Gigabud Banking Attacks<\/title>\n<meta name=\"description\" content=\"Android Work Profile abuse lets Gigabud and Vwork hide banking fraud. Explore the attack and how enterprises can strengthen Android security.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Android Work Profile Abuse: Gigabud Banking Attacks\" \/>\n<meta property=\"og:description\" content=\"Android Work Profile abuse lets Gigabud and Vwork hide banking fraud. Explore the attack and how enterprises can strengthen Android security.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-18T08:23:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T09:12:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Android Work Profiles Become a Banking Malware Hideout\",\"datePublished\":\"2026-09-18T08:23:20+00:00\",\"dateModified\":\"2026-09-21T09:12:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/\"},\"wordCount\":959,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp\",\"articleSection\":[\"Malware\",\"Mobile\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/\",\"name\":\"Android Work Profile Abuse: Gigabud Banking Attacks\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp\",\"datePublished\":\"2026-09-18T08:23:20+00:00\",\"dateModified\":\"2026-09-21T09:12:37+00:00\",\"description\":\"Android Work Profile abuse lets Gigabud and Vwork hide banking fraud. Explore the attack and how enterprises can strengthen Android security.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Android Work Profiles Become a Banking Malware Hideout\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/android-work-profiles-become-a-banking-malware-hideout\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Android Work Profiles Become a Banking Malware Hideout\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Android Work Profile Abuse: Gigabud Banking Attacks","description":"Android Work Profile abuse lets Gigabud and Vwork hide banking fraud. Explore the attack and how enterprises can strengthen Android security.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/","og_locale":"en_US","og_type":"article","og_title":"Android Work Profile Abuse: Gigabud Banking Attacks","og_description":"Android Work Profile abuse lets Gigabud and Vwork hide banking fraud. Explore the attack and how enterprises can strengthen Android security.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-18T08:23:20+00:00","article_modified_time":"2026-09-21T09:12:37+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Android Work Profiles Become a Banking Malware Hideout","datePublished":"2026-09-18T08:23:20+00:00","dateModified":"2026-09-21T09:12:37+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/"},"wordCount":959,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp","articleSection":["Malware","Mobile"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/","url":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/","name":"Android Work Profile Abuse: Gigabud Banking Attacks","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp","datePublished":"2026-09-18T08:23:20+00:00","dateModified":"2026-09-21T09:12:37+00:00","description":"Android Work Profile abuse lets Gigabud and Vwork hide banking fraud. Explore the attack and how enterprises can strengthen Android security.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android-Work-Profiles-Become-a-Banking-Malware-Hideout.png?format=webp","width":1340,"height":700,"caption":"Android Work Profiles Become a Banking Malware Hideout"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/android-work-profiles-become-a-banking-malware-hideout\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Android Work Profiles Become a Banking Malware Hideout"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1772","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1772"}],"version-history":[{"count":7,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1772\/revisions"}],"predecessor-version":[{"id":1827,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1772\/revisions\/1827"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1789"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1772"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1772"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}