Pix Pirate: new malware targets Pix and Brazilian financial institutions

Brazilian financial institutions and Pix users must be aware of yet another new threat to security and privacy. After the Central Bank of Brazil payment platform became popular, a new malware focusing on fraudulent transactions was recently discovered.

Called “PixPirate”, the banking trojan specifically targets Pix and applies its scams through Android devices. The threat can steal passwords entered in banking applications, obtaining free access to the money invested there.

Once installed on financial or user devices, Pix Pirate can execute a series of online attacks and security risks, as:

  • Interception of messages and SMS;
  • Serving unauthorized ads via push notification;
  • Uninstalling Google Play Protect;
  • Preventing malware from being uninstalled.

How Pix Pirate works?

Without users' knowledge, the new threat presents itself and installs itself on operating systems in the guise of authenticator applications. To operate your scams, uses accessibility services API to act on operating systems.

Yet, this new version of malware can run ATS, which is an automatic transfer system. This fact allows the agents behind the trojan to automate money transaction processes through the PIX platform..

Technologies such as encryption and obfuscation are breached by attackers using a framework called “Auto.js”. This mechanism would allow agents to resist reverse engineering.

Italian discovery

The new malware was discovered between the end of 2022 and beginning of 2023 by Cleafy, according to the website The Hacker News. This is an Italian cybersecurity company that, since then, has been tracking and monitoring the actions of malicious agents.

The trojan is just another banking malware that is now part of an extensive list of Android threats. One month before the discovery of Pix Pirate, the one entitled “BrasDex” had also been discovered.

Just like the new threat, This malware also has the ATS feature to carry out its financial scams.