'PixPirate' RAT Invisibly Triggers Wire Transfers From Android Devices
ID: da16bc2d-dc42-5bc8-86a0-1be439de1c62
STIX ID: report--da16bc2d-dc42-5bc8-86a0-1be439de1c62
Feed Name: Dark Reading
PixPirate is a sophisticated Android banking Trojan targeting Brazil's Pix payment platform that spreads via fake bank authentication apps delivered over WhatsApp or SMS, steals credentials and executes fraudulent transfers using overlays and automated interactions, and implements a novel iconless persistence technique where a downloader launches and binds to an exported payload service to avoid displaying an app icon; the campaign leverages accessibility abuse and other capabilities (keylogging, device control, persistence) and threatens financial users at scale given Pix's large user base.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
