PixRevolution Malware Targets Brazil's PIX Payment System in Real Time
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Zimperium's zLabs has identified a new Android banking trojan named PixRevolution, specifically designed to hijack Brazil's PIX instant payment system. This malware exploits the rapid and irreversible nature of PIX transactions, which have over 150 million users and process more than 3 billion transactions monthly. PixRevolution operates by monitoring victims' smartphones in real time, replacing the recipient's payment key with one controlled by attackers during the transaction. The malware remains dormant until a PIX transfer is initiated, displaying a fake loading screen to cover its malicious activities. Attackers distribute the malware through fraudulent Google Play Store pages that mimic legitimate apps. The trojan requires users to grant extensive accessibility permissions, allowing it to read screen content and simulate taps. The threat is significant due to the high volume of transactions and the lack of chargeback options for victims.
Key Points: • PixRevolution targets Brazil's PIX payment system, affecting over 150 million users. • The malware uses real-time monitoring and operator intervention to redirect funds during transactions. • Fraudulent app distribution mimics legitimate Google Play Store listings to install the trojan.