Android work profiles can hide a cloned banking app

The signal in one glance
What you need to know
- A banking Trojan known as Gigabud can reportedly create a second copy of a legitimate banking application inside an Android work profile.
- This technique shifts the warning sign from an obviously unfamiliar application to an unexpected Android profile and its associated management controls.
- Action: Review Android work profiles and device-management applications; remove only items you can verify as unauthorized, and preserve evidence before resetting a suspected device.
What happened
A banking Trojan known as Gigabud can reportedly create a second copy of a legitimate banking application inside an Android work profile. The separation can make the malicious or manipulated app less visible during a quick check of the phone’s normal app list, while allowing attackers to interfere with banking activity or conceal fraudulent transactions.