
Gigabud forks Shelter to weaponize Android work profiles against banking app checks
Gigabud's Vwork abuse of work profiles reveals how malware repurposes Android's enterprise features to defeat app-level integrity checks. The Shelter fork demonstrates rapid adaptation from public defensive code. Confirmed Indonesian losses near $9M signal the tactic will spread to other sampled regions once development matures.
Group-IB's September 9 report traces the chain: Gigabud first requests Accessibility and overlay permissions, then installs Vwork within minutes. Vwork strips Shelter's multi-screen user flow to a single Chinese-language prompt, creates the profile, and clones a fake banking app inside it. Banking apps' on-device scans cannot reach the personal profile where the RAT sits, allowing operators to run transactions under a black overlay while Accessibility captures input. Samples target twelve countries yet only Indonesia shows full execution. Vwork's class names and architecture match the open-source Shelter tool exactly except for removed permission checks and external command hooks. This pattern shows malware authors systematically monitoring defensive open-source projects and stripping safety gates within months of release. The technique exploits Android's BYOD isolation model, which any app can initiate, rather than a zero-day. Unstable functions noted on AOSP builds indicate operators are iterating across device fleets. Expansion beyond Indonesia is probable once Vwork stabilizes.
Group-IB: Vwork will appear in at least three additional countries with confirmed infections inside 120 days
Sources (2)
- [1]Group-IB Gigabud Technical Report(https://www.group-ib.com/blog/gigabud-vwork-2026)
- [2]The Hacker News coverage(https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html)