What Happened
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That
Why It Matters
Report facts: The Gigabud banking trojan now deploys a second Android app that creates a work profile on infected devices and installs a tampered banking app inside that isolated space, helping the malware evade standard banking app integrity and security checks. This technique targets mobile banking environments, undermining users’ trust in the authenticity of the banking app and its runtime protections. RealGround analysis: While the article does not explicitly mention AI, fintech ecosystems increasingly embed AI-driven fraud detection and behavioral analytics in mobile banking apps, which can be blinded or bypassed if malware runs inside deceptive app instances or segregated profiles. Financial institutions should conduct structured AI Security Readiness Assessments to ensure their AI-powered risk engines and app integrity checks monitor for profile-based evasion techniques and anomalous app installations, and to harden mobile AI telemetry against tampering in work-profile or containerized environments.
RealGround Analysis
This signal maps to fintech AI risk. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html
