GoPix banking Trojan targeting Brazilian financial institutions
GoPix is an advanced persistent threat targeting Brazilian financial institutions and cryptocurrency users. It uses memory-only implants and obfuscated PowerShell scripts, evolving from previous RAT and ATS threats. The malware employs sophisticated techniques, including malvertising via Google Ads, man-in-the-middle attacks, and monitoring of Pix transactions and Boleto slips. GoPix bypasses security measures, maintains persistence, and uses robust cleanup mechanisms. It leverages multiple obfuscation layers and a stolen code signing certificate to evade detection. The threat actors carefully select victims, including financial bodies of state governments and large corporations, using legitimate anti-fraud services for targeted delivery.
Pulse ID: 69b81e54cf83df8f4401d65d
Pulse Link: https://otx.alienvault.com/pulse/69b81e54cf83df8f4401d65d
Pulse Author: AlienVault
Created: 2026-03-16 15:14:28
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #GoPIX #Google #GoogleAds #Government #InfoSec #Malvertising #Malware #OTX #OpenThreatExchange #PowerShell #RAT #SMS #Trojan #bot #cryptocurrency #AlienVault