PixBankBot: ATS Malware Threatens Brazil's Banking
ID: bad7abcb-d850-5b41-84d8-090ee464c3ce
STIX ID: report--bad7abcb-d850-5b41-84d8-090ee464c3ce
Feed Name: Cyble Blog
PixBankBot is an ATS-based Android banking trojan that masquerades as a PDF app and abuses Android Accessibility Service to keylog, create overlay windows, fetch attacker Pix keys, insert transfer amounts, auto-confirm transactions (including social-engineering biometric prompts), exfiltrate transfer logs to a C2 (http://proctrt.sytes.net/tra/a.php), and self-delete under certain conditions; the report provides APK metadata, multiple file hashes, attack flow, ATT&CK mappings, and mitigation recommendations for users and banks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
