The bank's app caught the malware. The money left from the work profile, where the bank could not see it
2026-09-11Security
Group-IB found GoldFactory's Gigabud trojan using a Shelter fork called Vwork to create an Android work profile and clone a banking app into it. The bank's malware check had already fired in the personal profile. The fraudulent transfer came from the other side of the wall, looking like a clean new device.