The Gigabud banking trojan has evolved with a new tactic that abuses a legitimate Android enterprise feature to create a hidden sandbox for malicious activity, allowing it to bypass standard security checks.
According to a report from security firm Group-IB, the updated malware uses a tool called Vwork to install a secondary application which creates a "work profile" on an infected device. It then deploys a tampered version of a banking application within this separate, managed space. Android's work profile is designed to containerize corporate apps and data, keeping them isolated from a user's personal apps.
This method creates a significant detection blind spot. Security software and the banking application's own tamper-detection mechanisms typically scan only the device's primary personal space. By operating entirely within the confines of the work profile, the malicious banking app evades this scrutiny.
The technique represents a notable shift in threat strategy, moving from exploiting software vulnerabilities to weaponizing core operating system functionalities designed for enterprise management. This complicates defense strategies, as security tools and analysts must now extend their focus to encompass threats within all segmented profiles on a device.
Users are advised to be vigilant against unexpected prompts requesting the setup of a work profile and to ensure applications are downloaded exclusively from official sources. The discovery underscores the need for comprehensive security solutions that can monitor activity across all containerized profiles on a mobile device.
Gigabud銀行木馬病毒採用全新手法,濫用Android企業合法功能創建隱藏沙箱從事惡意活動,藉此規避標準保安檢查。
根據保安公司Group-IB的報告,這款升級版惡意軟件使用名為Vwork的工具安裝次要應用程式,在受感染設備上建立「工作設定檔」。隨後將經篡改的銀行應用程式部署於此獨立管理空間內。Android的工作設定檔功能旨在將企業應用程式與數據隔離,使其與用戶個人應用程式完全分隔。
此方法構成顯著的偵測盲點。保安軟件及銀行應用程式自身的防篡改機制通常僅掃描設備的主要個人空間。透過完全在工作設定檔範圍內運作,惡意銀行應用程式得以避開這些監察。
此技術代表威脅策略的重大轉變——從利用軟件漏洞轉向將核心操作系統功能武器化(該功能原為企業管理而設計)。這使防禦策略複雜化,因保安工具及分析人員現需將關注範圍擴展至設備所有分隔設定檔內的威脅。
用戶應警惕未經請求的工作設定檔設置提示,並確保僅從官方來源下載應用程式。此次發現突顯了全面保安解決方案的必要性——此類方案應能監察流動設備所有容器化設定檔中的活動。
