Ethical Hacking News
A new Trojan horse has been discovered, which uses the work profile feature on Android devices to gain unauthorized access to sensitive information. Meet Vwork, a highly sophisticated Trojan that has been linked to the notorious Gigabud banking trojan, and is wreaking havoc on Android devices across the globe. Learn more about the Vwork Trojan and how to protect yourself against this threat.
Vwork is a remote access Trojan (RAT) that uses the work profile feature on Android devices to gain unauthorized access to sensitive information. The Vwork Trojan creates a separate work profile on an infected device and installs a modified version of the Shelter app to gain access to sensitive information. Vwork has been linked to the GoldFactory group, which is also responsible for the Gigabud banking trojan. The Trojan has been used to steal sensitive information, including login credentials, and has also been used to install malware on Android devices. Vwork uses advanced techniques to evade detection, including encryption and anti-debugging techniques. Users are advised to take steps to protect themselves against the Vwork Trojan, including installing apps from official stores and using a reputable antivirus software.
The world of mobile security is a complex and ever-evolving landscape, where threats lurk in every corner, waiting to pounce on unsuspecting users. In recent times, a new player has emerged in the world of mobile security, one that has been making waves in the cybersecurity community with its sophisticated and insidious tactics. Meet Vwork, a Trojan horse that has been linked to the notorious Gigabud banking trojan, and is wreaking havoc on Android devices across the globe.
According to a recent report published by Group-IB, a leading cybersecurity firm, Vwork is a remote access Trojan (RAT) that uses the work profile feature on Android devices to gain unauthorized access to sensitive information. This feature, designed to segregate work-related apps from personal data, has been co-opted by Vwork to create a backdoor for hackers to exploit.
The Vwork Trojan works by creating a separate work profile on an infected device, and then installing a modified version of the Shelter app, which is an open-source tool used to isolate or duplicate apps on Android devices. However, unlike Shelter, Vwork opens the same jobs to other apps, allowing hackers to drive the Trojan and gain access to sensitive information.
The report also reveals that Vwork has been seen in the wild only in a campaign of tampered banking apps in Southeast Asia, which was discovered by Group-IB in December 2025. The Trojan has been linked to the GoldFactory group, which is also responsible for the Gigabud banking trojan.
The report highlights that Vwork has been used to steal sensitive information, including login credentials, and has also been used to install malware on Android devices. The Trojan has also been used to intercept web traffic, and has been linked to a number of high-profile attacks in Southeast Asia.
The Group-IB report warns that Vwork is a highly sophisticated Trojan that uses advanced techniques to evade detection, including the use of encryption and anti-debugging techniques. The report also warns that Vwork can be used to steal sensitive information, including login credentials, and can also be used to install malware on Android devices.
In light of these findings, cybersecurity experts are urging users to be vigilant and take steps to protect themselves against the Vwork Trojan. This includes installing apps only from official stores, refusing Accessibility access to any app that is not an accessibility tool, and using a second factor for banking apps that does not rely on SMS.
The report also highlights the importance of regular device updates and security patches, as well as the need for users to regularly back up their data to a secure location. Additionally, users are advised to use a reputable antivirus software and to regularly scan their devices for malware.
In conclusion, the Vwork Trojan is a highly sophisticated and insidious threat that uses advanced techniques to evade detection. The report highlights the importance of vigilance and taking steps to protect oneself against this threat. By understanding the tactics and techniques used by Vwork, users can take steps to protect themselves against this Trojan and prevent future attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Dark-Underbelly-of-Mobile-Security-Uncovering-the-Vwork-Trojan-and-Its-Sinister-Plans-ehn.shtml
https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html
https://cybersecuritynews.com/hackers-clone-banking-apps/
https://www.group-ib.com/blog/gigabud-banking-malware/
https://malpedia.caad.fkie.fraunhofer.de/actor/goldfactory
https://www.group-ib.com/masked-actors/goldfactory/
Published: Thu Sep 10 11:51:09 2026 by llama3.2 3B Q4_K_M