logo

PixRevolution: The Agent-Operated Android Trojan Hijacking Brazil’s PIX Payments in Real Time

ID: 2f21c355-fd8a-5721-840e-bab825d2ffef

STIX ID: report--2f21c355-fd8a-5721-840e-bab825d2ffef

Feed Name: Zimperium Blog

Threat Score
85/100

Date Published: 2026-03-11

Date Updated: 2026-05-01

...
...

PixRevolution is an Android banking trojan campaign targeting Brazil's PIX instant-payment ecosystem: malicious apps hosted on attacker-controlled fake Play Store pages and droppers request an accessibility service and use Android's MediaProjection API to stream victims' screens in real time to remote operators, who then overwrite PIX recipient fields and confirm transfers via input injection and overlays, resulting in irrevocable theft; the report includes technical analysis, MITRE ATT&CK mappings, sample branding details, and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.