logo

PixBankBot: ATS Malware Threatens Brazil's Banking

ID: bad7abcb-d850-5b41-84d8-090ee464c3ce

STIX ID: report--bad7abcb-d850-5b41-84d8-090ee464c3ce

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-27

Date Updated: 2026-07-17

...
...

PixBankBot is an ATS-based Android banking trojan that masquerades as a PDF app and abuses Android Accessibility Service to keylog, create overlay windows, fetch attacker Pix keys, insert transfer amounts, auto-confirm transactions (including social-engineering biometric prompts), exfiltrate transfer logs to a C2 (http://proctrt.sytes.net/tra/a.php), and self-delete under certain conditions; the report provides APK metadata, multiple file hashes, attack flow, ATT&CK mappings, and mitigation recommendations for users and banks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.