logo

Real-Time Banking Trojan Strikes Brazil's Pix Users

ID: 854353a0-1c89-5db2-ac04-b1e49e97469f

STIX ID: report--854353a0-1c89-5db2-ac04-b1e49e97469f

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-03-13

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

## Executive summary PixRevolution is an Android banking Trojan targeting Brazil's widely used Pix payment system; it infects users via fake Play Store pages, requests a malicious accessibility option, then enables real-time screen capture and operator/AI-driven hijacking of transactions (C2 on port 9000, HTML overlays and transaction-related keyword monitoring). The report highlights the malware's precision timing, social-engineering distribution, and the recommendation that financial institutions integrate mobile threat visibility into fraud detection and authentication workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.