‘PixRevolution’ Android Trojan Hijacks Brazil’s PIX in Real-Time
ID: fc439ad3-a61d-53da-9459-c38879bd33e5
STIX ID: report--fc439ad3-a61d-53da-9459-c38879bd33e5
Feed Name: securityonline.info
Zimperium zLabs uncovered "PixRevolution," an Android banking trojan targeting Brazil's PIX payment system that uses social engineering and Android Accessibility Services to stream victims' screens to a human/AI operator via a persistent TCP connection; the operator performs live recipient-key swaps during transfers while displaying a brief overlay so victims see a completed transfer, making rapid recovery unlikely. The malware shows operational polish (hardcoded Brazilian bank logos, monitoring of Portuguese financial phrases) and is distributed via fake Google Play Store listings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
