Kaspersky
GoPix Trojan Targets Brazilian Financial Sector with Advanced Techniques
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
GoPix is a sophisticated banking Trojan that has been actively targeting Brazilian financial institutions and cryptocurrency users for over three years. The malware employs memory-only implants and utilizes malvertising through Google Ads to lure victims into malicious landing pages. It executes man-in-the-middle attacks to monitor and manipulate Pix transactions and Boleto slips. As of March 2026, Kaspersky has detected 90,000 infection attempts attributed to GoPix. The threat actors behind GoPix adopt techniques similar to advanced persistent threat (APT) groups, ensuring persistence and evasion of detection by employing minimal artifacts on disk. The malware's command and control servers have a very short lifespan, complicating detection efforts. GoPix's stealthy methods and evolving capabilities make it a significant concern for financial institutions in Brazil.
Key Points: • GoPix has been active for over three years, targeting Brazilian financial institutions. • The Trojan uses malvertising via Google Ads to lure victims and evade detection. • As of March 2026, there have been 90,000 detected infection attempts attributed to GoPix.