Gigabud, a sophisticated Android banking trojan posing as governmental institutions, initially focused its attacks on Thailand, the Philippines, and Peru. Its code exhibits significant similarities with Golddigger, another Android banking trojan active in Vietnam.
This overlap suggests a common threat actor who has since broadened Gigabud’s reach to include Bangladesh, Indonesia, Mexico, South Africa, and Ethiopia, reflecting an increased level of sophistication and geographic scope.
Recent investigations have uncovered phishing sites that mimic Google Play, disguising themselves as South African Airways and Ethiopian Airlines to lure users into downloading the malicious Gigabud apps. The use of African airline themes and malware samples from South Africa points to an expansion of targets to include both South Africa and Ethiopia.
Gigabud has further extended its operations to Mexico and Indonesia, masquerading as HeyBanco and M-Pajak through deceptive login pages.
Since June 2024, there has been a noticeable surge in Gigabud’s distribution, indicating an intensified campaign. The malware shares code with Golddigger, suggesting a shared origin. Its use of varied icons to impersonate legitimate entities underscores its reliance on social engineering to deceive victims.
New Gigabud samples have been found employing the Virbox packer to obscure their malicious intent. This obfuscation strategy, similar to that used by Golddigger, exploits the zip file format, making detection and analysis by security solutions more challenging.
Recent analyses reveal that Gigabud malware samples have a strong resemblance to Golddigger. Both variants utilize a native library, “libstrategy.so,” to target specific UI elements in banking apps. Gigabud has built on Golddigger’s framework by adding support for additional banking applications such as Yape (Peru) and Dutch-Bangla Bank Rocket (Bangladesh), indicating an evolution in its capabilities and highlighting the need for increased vigilance against mobile banking threats.
Samples once thought to be Golddigger have been reclassified as Gigabud following unpacking analysis, which revealed shared libraries and classes with known Gigabud variants.
A newly unpacked Gigabud sample, distributed through a phishing site, does not use Virbox packing but retains code similarities to earlier versions, especially in its fraudulent bank dialog boxes.
Recent Gigabud samples utilize Retrofit for command and control (C&C) communication and include endpoints for uploading user data such as contacts, SMS, and screen recordings. The malware’s strategy involves leveraging the libstrategy.so library, also employed by Golddigger, to target specific UI elements of banking apps and steal financial information. This reuse of libraries suggests the same threat actor is responsible for both malware strains.
According to Cyble Intelligence and Research Labs, there is a significant connection between Golddigger and Gigabud malware, pointing to a single attacker behind both. The recent proliferation of Gigabud samples and the use of shared techniques highlight a more sophisticated approach and a broader targeting range.
The emergence of new features and attacks in regions such as Bangladesh, Indonesia, Mexico, South Africa, and Ethiopia emphasizes the evolving nature of the threat, confirming the need for heightened vigilance and advanced security measures.



