logo

PixPirate Android Banking Trojan Using New Evasion Tactic to Target Brazilian Users

ID: 90177077-a1b3-5161-b19b-af066a0737e5

STIX ID: report--90177077-a1b3-5161-b19b-af066a0737e5

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-03-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes active financial fraud campaigns in Latin America: PixPirate, an Android banking trojan targeting Brazil, now uses a technique that omits launcher intents to hide its icon while a downloader and droppee cooperate to run and persist via exported services and receivers, enabling covert theft of credentials, SMS interception, keystroke capture, and unauthorized PIX transfers; separately, Fakext abused a rogue Microsoft Edge extension (SATiD) to perform web injections and overlays to steal banking credentials across multiple LATAM banks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.