logo

Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets

ID: c90be07a-9feb-550e-9118-f114393c671c

STIX ID: report--c90be07a-9feb-550e-9118-f114393c671c

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Cybersecurity researchers identified multiple Android malware families (PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, Oblivion RAT, SURXRAT, BTMOB) being distributed via fake Google Play Store pages and phishing; these samples abuse Android accessibility and MediaProjection APIs, use overlays to hijack Pix and cryptocurrency transfers, exfiltrate credentials and device data, include crypto-miners and remote administration features, are marketed as MaaS on Telegram and other forums, and show experimentation with LLM components and ransomware-style screen lockers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.