logo

Free real estate: GoPix, the banking Trojan living off your memory

ID: c5bb940c-e7d6-5a0d-b4f0-c4ba28d2bd4a

STIX ID: report--c5bb940c-e7d6-5a0d-b4f0-c4ba28d2bd4a

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2026-03-16

Date Updated: 2026-04-29

Author: GReAT

...
...

GoPix is an advanced, active banking Trojan campaign targeting Brazilian financial-institution customers and cryptocurrency users via malvertising (Google Ads), staged PowerShell loaders, memory-only implants, and novel PAC-based MITM interception that injects trusted root certificates into browser memory; the report documents the full infection chain, evasion techniques, targeted objectives (Pix, Boleto, crypto wallets), and includes technical indicators (hashes, domains, certificate thumbprints).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.