PixPirate Android malware uses new tactic to hide on phones
ID: 915a704f-593b-5028-a9b5-89f5abeb3e47
STIX ID: report--915a704f-593b-5028-a9b5-89f5abeb3e47
Feed Name: Bleeping Computer
PixPirate is an Android banking trojan targeting Brazilian Pix users that uses a downloader/droppee two-app design to remain hidden and persistent: the payload (droppee) intentionally omits a launcher icon and exposes an exported service that the downloader binds to in order to start malicious activity. The malware requests Accessibility permissions, can automate fraudulent Pix transfers and 2FA interception in the background, is distributed via APKs sent over WhatsApp/SMS, and can persist and launch on system events even if the initial downloader is removed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
