Free real estate: GoPix, the banking Trojan living off your memory
ID: c5bb940c-e7d6-5a0d-b4f0-c4ba28d2bd4a
STIX ID: report--c5bb940c-e7d6-5a0d-b4f0-c4ba28d2bd4a
Feed Name: Securelist by Kaspersky
GoPix is an advanced, active banking Trojan campaign targeting Brazilian financial-institution customers and cryptocurrency users via malvertising (Google Ads), staged PowerShell loaders, memory-only implants, and novel PAC-based MITM interception that injects trusted root certificates into browser memory; the report documents the full infection chain, evasion techniques, targeted objectives (Pix, Boleto, crypto wallets), and includes technical indicators (hashes, domains, certificate thumbprints).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
