GoPix Trojan Targets Brazilian Financial Sector with Advanced Techniques

GoPix Trojan Targets Brazilian Financial Sector with Advanced Techniques

First seen 16 Mar 2026, 19:37 UTC SecurelistKaspersky 82% similarity 69.5

Article Content

Browse articles
ThreatCluster

GoPix is a sophisticated banking Trojan that has been actively targeting Brazilian financial institutions and cryptocurrency users for over three years. The malware employs memory-only implants and utilizes malvertising through Google Ads to lure victims into malicious landing pages. It executes man-in-the-middle attacks to monitor and manipulate Pix transactions and Boleto slips. As of March 2026, Kaspersky has detected 90,000 infection attempts attributed to GoPix. The threat actors behind GoPix adopt techniques similar to advanced persistent threat (APT) groups, ensuring persistence and evasion of detection by employing minimal artifacts on disk. The malware's command and control servers have a very short lifespan, complicating detection efforts. GoPix's stealthy methods and evolving capabilities make it a significant concern for financial institutions in Brazil.

Key Points: • GoPix has been active for over three years, targeting Brazilian financial institutions. • The Trojan uses malvertising via Google Ads to lure victims and evade detection. • As of March 2026, there have been 90,000 detected infection attempts attributed to GoPix.

ThreatCluster AI How this analysis works

Timeline

2023-01-05
GoPix identified as an advanced threat.
2023-12-01
Malvertising campaign using Google Ads initiated.
2026-03-16
Kaspersky reports 90,000 infection attempts detected.

Community

Browse all →

Tracked Entities in This Story