logo

Ghost in the Browser: Advanced ‘GoPix’ Trojan Unveils Unprecedented MitM Attacks

ID: e48cc8b2-770b-5de2-ae03-aa0c73eee760

STIX ID: report--e48cc8b2-770b-5de2-ae03-aa0c73eee760

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-19

Date Updated: 2026-04-23

Author: Ddos

...
...

GoPix is a sophisticated Brazilian-origin banking Trojan that employs living-off-the-land techniques, memory-only implants, stolen code-signing certificates, encrypted shellcode, and browser-memory root certificate injection to perform unprecedented in-memory MITM against banking sites and payment systems (Pix, Boleto). It spreads via highly targeted malvertising and uses reputation/IP scoring to selectively deliver payloads to valuable victims while leveraging short-lived C2 infrastructure and aggressive anti-analysis measures to evade detection and forensic attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.