
Gigabud Android Banking Trojan Ransomware: Hidden App Clones Enable Fraud (June 2026)
Gigabud: What Happened
The Gigabud Android banking trojan has been confirmed to exploit a novel technique involving the creation of hidden work profiles on infected mobile devices. By tricking users into sideloading malicious applications, Gigabud establishes a secondary, concealed environment where it installs cloned versions of legitimate banking apps. This allows threat actors to conduct fraudulent transactions isolated from the device's primary profile, significantly reducing the likelihood of detection by anti-fraud and anti-malware solutions. The campaign is global in scope, with no specific organizations listed as primary targets, indicating a broad threat to Android users worldwide.
Attack Vector & Technical Detail
Initial infection occurs when victims are deceived into sideloading fake applications that request extensive permissions, including access to device administration and accessibility services. Once installed, Gigabud leverages these permissions to create a hidden work profile, within which it deploys cloned banking applications. The malware uses overlays to steal banking credentials and device PINs, and can remotely control the cloned apps to initiate unauthorized transactions. Key indicators of compromise include Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, Android/Trojan.Banker.ACR6C67829FH20, Android/Trojan.Banker.SIB02FFFFFF1112H106, Android/Trojan.Banker.SIB0181193e44H71, Android/Trojan.Banker.AUR2f2f4fb5C95, and Android/Trojan.Spy.Gigabud.xc. The attack aligns with MITRE tactics TA0006 (Credential Access), TA0009 (Collection), and TA0011 (Command and Control), underscoring its sophistication and multi-stage approach.
Confirmed Impact
The primary impact is financial fraud, as Gigabud enables attackers to bypass traditional anti-fraud and malware detection systems that do not correlate activity across Android profiles. Victims may experience unauthorized transactions and direct compromise of their banking credentials. The global reach of this campaign increases the risk for users in all regions, and the use of hidden work profiles complicates incident response and forensic investigation. While no specific regulatory breaches have been cited, the potential for large-scale credential theft and financial loss is significant, especially for organizations with employees using Android devices for work-related banking.
What This Means for Your Organization
The Gigabud campaign highlights the evolving threat landscape for mobile banking and the limitations of current detection mechanisms on Android devices. Organizations should review their mobile device management (MDM) policies to restrict sideloading of applications and enforce least-privilege access for device permissions. Security teams must be aware that malicious activity can occur within hidden work profiles, which may not be visible to standard endpoint protection tools. User education is critical to prevent installation of unauthorized apps, and regular security audits should include checks for anomalous profiles and app installations.
Detection & Response
- Immediate: Audit all Android devices for unauthorized work profiles and unknown banking app installations.
- Hunt: Search for presence of IOCs such as Android/Trojan.Banker.ACR577B2BA2H61, Android/Trojan.Banker.ACRF6CE8D30H46, and Android/Trojan.Spy.Gigabud.xc.
- Patch: N/A (no CVEs associated with this campaign; focus on policy enforcement and user awareness).
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

