Ghost in the Browser: Advanced ‘GoPix’ Trojan Unveils Unprecedented MitM Attacks
ID: e48cc8b2-770b-5de2-ae03-aa0c73eee760
STIX ID: report--e48cc8b2-770b-5de2-ae03-aa0c73eee760
Feed Name: securityonline.info
GoPix is a sophisticated Brazilian-origin banking Trojan that employs living-off-the-land techniques, memory-only implants, stolen code-signing certificates, encrypted shellcode, and browser-memory root certificate injection to perform unprecedented in-memory MITM against banking sites and payment systems (Pix, Boleto). It spreads via highly targeted malvertising and uses reputation/IP scoring to selectively deliver payloads to valuable victims while leveraging short-lived C2 infrastructure and aggressive anti-analysis measures to evade detection and forensic attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
