Gigabud uses Android app cloning to separate fraud from malware alerts

BRIEF
Gigabud is using Android’s work-profile and app-cloning capabilities to create a second environment for banking applications. The reported objective is to weaken the connection between a device’s malware signals and suspicious banking activity, making fraud harder for automated controls to link to the infected environment. This is an evasion technique, not proof that every cloned banking app session will bypass a bank’s defenses. The supplied research supports the app-cloning and fraud-evasion findings, but it does not establish how widely the technique is being used, which banks are affected, or how much money has been stolen. Attacker-controlled software may present the cloned environment as a normal or safer place to use a banking app; that is an attacker claim, not a security guarantee. Organizations should treat unexpected work-profile creation, cloned financial apps, and changes in application context as signals for investigation. Consumers should also avoid assuming that a bank app is safe merely because it opens normally or appears isolated from other applications.
WHY IT MATTERS
Many mobile fraud controls depend on connecting suspicious device behavior with activity inside a banking app. App cloning can complicate that connection by moving the financial session into a separate Android context. That does not make the transaction legitimate, but it can reduce the usefulness of simple device-based alerts and increase the value of account, transaction, and behavioral controls. The available reporting confirms the technique and its intended fraud-evasion purpose, while leaving its scale and effectiveness uncertain. Teams should therefore focus on layered detection rather than relying on one malware signal or one application installation context.