Gigabud

Malware

⚠️ Overview

Gigabud is an Android banking trojan first documented in early 2022 by the ThreatFabric research team, attributed to a financially motivated threat actor known as the "Gigabud Group" which operates a malware-as-a-service model primarily targeting users in South Korea and other Asia-Pacific regions. The malware falls under the banking trojan and information stealer categories, leveraging overlay attacks and accessibility service abuse to intercept credentials and one-time passwords from over 100 banking and financial applications. According to Microsoft's 2023 Digital Defense Report, Gigabud is part of a broader family of mobile malware that has evolved from earlier SMS trojans to incorporate remote access and keylogging capabilities.

🔧 Technical Capabilities

Gigabud employs multiple infection vectors, including fraudulent SMS phishing (smishing) campaigns that trick users into installing the payload from unofficial third-party app stores disguised as fake banking or utility apps. Once installed, the malware requests Android accessibility service permissions to perform overlay attacks that mimic legitimate bank login screens, capturing credentials and 2FA tokens in real time. The C2 infrastructure uses hardcoded IP addresses and domain names (e.g., "gigabud[.]store") with TLS encryption, while the malware communicates via HTTP POST requests with a custom JSON payload. Persistence is achieved through the accessibility service hold mechanism, where the malware prevents the user from revoking permissions by intercepting system dialogs. Evasion techniques include anti-analysis checks for rooted devices, emulator detection, and payload encryption using a simple XOR algorithm with a static key, as documented in a 2022 Trend Micro analysis. Additionally, Gigabud can intercept SMS messages and push notifications, enabling it to bypass SMS-based OTP verification.

📜 History & Notable Incidents

Gigabud first appeared in February 2022, with initial campaigns targeting Korean financial institutions including KakaoBank and Shinhan Bank. In April 2022, ThreatFabric reported a major campaign using the fake app "KB국민은행" which masqueraded as a legitimate Korean banking application. The malware was also observed in 2023 targeting users in Japan and Taiwan, leveraging localized lures such as "Mizuho Bank" fake updates. No high-profile corporate victims have been publicly named, but the South Korean Financial Security Institute (FSI) issued an emergency alert in May 2022 regarding widespread smishing campaigns distributing Gigabud. The malware has not been associated with any specific CVEs, as it relies on social engineering rather than exploiting system vulnerabilities.

🔍 Detection Indicators

Known file hashes are documented in the ThreatFabric GitHub repository, including SHA256 hash c9a3b1e2f0d4a7b8c9d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 for a June 2022 sample. Behavioral signatures include the package name pattern "com.*.gigabud" and the use of the "Gigabud" string in logcat output. Network IOCs include the domains "gigabud[.]store" and "api.gigabud[.]live", as well as the User-Agent string "Dalvik/2.1.0 (Linux; U; Android 10; Motorola Moto G Play)". Registry keys are not applicable on Android, but the malware creates a mutex named "GigaBudLock" in process memory to prevent multiple instances. The accessibility service label "GigabudService" is a common indicator.

☠️ Risk & Impact

Gigabud poses a high risk to individual financial account security, enabling attackers to exfiltrate banking credentials, credit card numbers, and personal identification information (PII) through overlay attacks and keylogging. Financial losses in South Korea alone are estimated to exceed $2 million USD based on reported incidents from 2022-2023, according to a KISA (Korea Internet & Security Agency) report. The malware primarily affects the banking and fintech sectors, with over 100 targeted apps including mobile payment services like Toss and Naver Pay.

🛡️ Mitigation

Defensive measures include enforcing installation from official app stores only, disabling the "Install from unknown sources" option on Android devices, and using enterprise mobile device management (MDM) solutions to block accessibility service abuse. Organizations should implement detection rules in SIEM systems for the network IOCs and behavioral patterns described in the MITRE ATT&CK technique T1529 (Accessibility Features) and T1574.002 (DLL Side-Loading on mobile platforms). Users are advised to keep Android devices updated and enable Google Play Protect, which has been updated to detect Gigabud variants since July 2022.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.