The banking app that made the payment was not the one on the phone
Android has a feature called a work profile: a sealed-off area of the phone where a company can put its own apps, kept separate from your photos and messages. It is a genuinely good idea. Group-IB published research on 9 September showing criminals have found a use for it that nobody intended.
The trojan is Gigabud, around since 2022, and it arrives the way these things usually do. A fake app impersonating a national airline, a tax office or a government portal, sideloaded from a link in a message or a social media post rather than an official store. On installation it asks for Accessibility access, permission to draw over other apps and an exemption from battery saving. Granted those, the operators can drive the phone remotely, list what is installed, drop convincing fake login screens over the real banking app and quietly record the lock screen code, all behind a black screen so the owner sees nothing.
The new move is a second app called Vwork, a stripped-down fork of the open source tool Shelter with its safety checks removed, presented in a single setup screen written in Chinese. Vwork creates a work profile and the bank's app is cloned into it. Security scanning in one profile largely cannot see into the other, so the warning raised in the personal space never connects to the transaction made from the work space, and the payment reaches the bank looking like it came from a device with no history of trouble. In Indonesia between February and July this year Group-IB counted around 1,469 compromised phones and losses of roughly $960,000. Samples built for this combination are aimed at eleven countries, including Brazil, Colombia, Egypt, Mexico, Thailand and Turkiye.
If you want to check your own phone, open Settings, then Passwords and accounts, and look for a Work tab you never set up. Beyond that: apps from official stores only, and never grant Accessibility access to something that is not an accessibility tool. The same instinct is what protects a PC, where the risk is usually an installer fetched from a search result. Tendvane's app updates run through winget, Microsoft's own package tool, so what installs comes from the publisher's real source rather than whichever download page ranked highest that day.