logo

PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time

ID: 86d373f0-a7ba-5531-8139-eacc191c0d3d

STIX ID: report--86d373f0-a7ba-5531-8139-eacc191c0d3d

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-03-12

Date Updated: 2026-04-22

...
...

A newly discovered Android banking trojan called PixRevolution targets Brazil's widely used PIX instant-payment system by abusing accessibility permissions to monitor screens, streaming those screens to remote operators, detecting payment activity, and briefly overlaying a fake loading screen while replacing the recipient's payment key so funds are redirected; it spreads via fraudulent download pages impersonating legitimate apps and poses a high-impact threat given PIX's large user base and irreversible transactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.