PixRevolution Malware Targets Brazil's PIX Payment System in Real Time

PixRevolution Malware Targets Brazil's PIX Payment System in Real Time

First seen 11 Mar 2026, 17:14 UTC FinextraIntelligentcisoZimperiumFeeds.FeedburnerInfosecurity-Magazine+1 89% similarity 69.0

Article Content

Browse articles
ThreatCluster

Zimperium's zLabs has identified a new Android banking trojan named PixRevolution, specifically designed to hijack Brazil's PIX instant payment system. This malware exploits the rapid and irreversible nature of PIX transactions, which have over 150 million users and process more than 3 billion transactions monthly. PixRevolution operates by monitoring victims' smartphones in real time, replacing the recipient's payment key with one controlled by attackers during the transaction. The malware remains dormant until a PIX transfer is initiated, displaying a fake loading screen to cover its malicious activities. Attackers distribute the malware through fraudulent Google Play Store pages that mimic legitimate apps. The trojan requires users to grant extensive accessibility permissions, allowing it to read screen content and simulate taps. The threat is significant due to the high volume of transactions and the lack of chargeback options for victims.

Key Points: • PixRevolution targets Brazil's PIX payment system, affecting over 150 million users. • The malware uses real-time monitoring and operator intervention to redirect funds during transactions. • Fraudulent app distribution mimics legitimate Google Play Store listings to install the trojan.

ThreatCluster AI

Timeline

2026-03-11
Zimperium identifies PixRevolution malware targeting PIX payments.
2026-03-12
Infosecurity-Magazine publishes findings on PixRevolution.

Community

Browse all →