• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups

    CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups

    Ransomware Attacks 2026

    Ransomware Attacks Have Soared 30% in Recent Months

    Flock Safety ALPR cameras

    Mountain View Shuts Down Flock Safety ALPR Cameras After Year-Long Unrestricted Data Access

    Lakelands Public Health cyberattack

    Lakelands Public Health Confirms Cyberattack, Says Sensitive Data Unaffected

    Foxit PDF Editor

    Foxit Releases Security Updates for PDF Editor Cloud XSS Vulnerabilities

    Spain Ban Social Media Platforms

    Spain Ban Social Media Platforms for Kids as Global Trend Grows

    French Police Raid X Offices as Grok Investigations Grow

    French Police Raid X Offices as Grok Investigations Grow

    social media ban for children France

    France Approves Social Media Ban for Children Under 15 Amid Global Trend

    vLLM

    Critical vLLM Flaw Exposes Millions of AI Servers to Remote Code Execution

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Spain Ban Social Media Platforms

    Spain Ban Social Media Platforms for Kids as Global Trend Grows

    social media ban for children France

    France Approves Social Media Ban for Children Under 15 Amid Global Trend

    ai cybersecurity webinar February 2026

    Lt Gen (Dr) Rajesh Pant to Lead Webinar on AI-Driven Cyber Threats — Register Free Now

    Japanese cybersecurity

    Britain and Japan Join Forces on Cybersecurity and Strategic Minerals

    online piracy

    U.S. and Bulgaria Shut Down Three Major Piracy Websites in EU Crackdown

    Data Privacy Week 2026-Interview

    Ad Fraud Is Exploding — Dhiraj Gupta of mFilterIt Explains How Brands Can Respond

    Proxy Network, Google, Google Threat Intelligence, Nation-State Actors,

    Google Dismantles Massive Proxy Network That Hid Espionage, Cybercrime for Nation-State Actors

    Data Privacy Week 2026

    Canada Marks Data Privacy Week 2026 as Commissioner Pushes for Privacy by Design

    European Commission investigation into Grok AI

    European Commission Launches Fresh DSA Investigation Into X Over Grok AI Risks

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups

    CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups

    Ransomware Attacks 2026

    Ransomware Attacks Have Soared 30% in Recent Months

    Flock Safety ALPR cameras

    Mountain View Shuts Down Flock Safety ALPR Cameras After Year-Long Unrestricted Data Access

    Lakelands Public Health cyberattack

    Lakelands Public Health Confirms Cyberattack, Says Sensitive Data Unaffected

    Foxit PDF Editor

    Foxit Releases Security Updates for PDF Editor Cloud XSS Vulnerabilities

    Spain Ban Social Media Platforms

    Spain Ban Social Media Platforms for Kids as Global Trend Grows

    French Police Raid X Offices as Grok Investigations Grow

    French Police Raid X Offices as Grok Investigations Grow

    social media ban for children France

    France Approves Social Media Ban for Children Under 15 Amid Global Trend

    vLLM

    Critical vLLM Flaw Exposes Millions of AI Servers to Remote Code Execution

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Spain Ban Social Media Platforms

    Spain Ban Social Media Platforms for Kids as Global Trend Grows

    social media ban for children France

    France Approves Social Media Ban for Children Under 15 Amid Global Trend

    ai cybersecurity webinar February 2026

    Lt Gen (Dr) Rajesh Pant to Lead Webinar on AI-Driven Cyber Threats — Register Free Now

    Japanese cybersecurity

    Britain and Japan Join Forces on Cybersecurity and Strategic Minerals

    online piracy

    U.S. and Bulgaria Shut Down Three Major Piracy Websites in EU Crackdown

    Data Privacy Week 2026-Interview

    Ad Fraud Is Exploding — Dhiraj Gupta of mFilterIt Explains How Brands Can Respond

    Proxy Network, Google, Google Threat Intelligence, Nation-State Actors,

    Google Dismantles Massive Proxy Network That Hid Espionage, Cybercrime for Nation-State Actors

    Data Privacy Week 2026

    Canada Marks Data Privacy Week 2026 as Commissioner Pushes for Privacy by Design

    European Commission investigation into Grok AI

    European Commission Launches Fresh DSA Investigation Into X Over Grok AI Risks

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

PixBankBot Targets Brazil’s Instant Payment Platform Pix

Pix is a fast and convenient instant payment platform developed and overseen by the Central Bank of Brazil (BCB), the country's monetary authority

Editorial by Editorial
May 30, 2023
in Firewall Daily
0
PixBankBot
672
SHARES
3.7k
VIEWS
Share on LinkedInShare on Twitter

Researchers have traced an Android banking trojan dubbed “PixBankBot” that accesses and abuses the popular Brazilian instant payment platform Pix.

The Android trojan PixBankBot is built on the ATS framework and uses the Accessibility Service to identify and track User Interface (UI) elements within targeted banking apps, particularly the instant payment platform Pix.

By doing so, PixBankBot can execute fraudulent transactions and capture sensitive information including account balances and money transfer details, found Cyble Research & Intelligence Labs (CRIL) researchers.

“An impressive statistic provided by Banco Central do Brasil reveals that over 138 million users have transacted using Pix as of April 2023; it’s clear that its popularity continues to soar,” said the CRIL report.

“However, as this innovative technology empowers users, it has also captured the attention of Threat Actors (TAs).”

PixBankBot: Pix and the popularity bane

Pix is a fast and convenient instant payment platform developed and overseen by the Central Bank of Brazil (BCB), the country’s monetary authority.

report-ad-banner

The Central Bank of Brazil internally designed and created the “Pix” brand name and logo in 2020.

Launched in the summer of 2019 and officially operational since November 16, 2020, Pix enables users to swiftly execute various types of payments and transfers.

Brazilian banks utilizing the Pix Instant Payment system are facing an ongoing onslaught from these relentless adversaries, the CRIL research report warned.

In the past six months, Cyble Research & Intelligence Labs (CRIL) has witnessed a surge in Android banking trojans specifically tailored to Brazilian banks.

PixBankBot
Timeline of ATS-based Banking Trojan targeting Brazilian banks – CRIL

The cases spotted recently include the Chameleon Android banking trojan, which targeted mobile users to capture SMS messages and maintain persistence, and ‘Zanubis’, which targeted over 40 banking applications from Peru.

These trojans employ the Automated Transfer System (ATS) framework to carry out fraudulent transactions, posing a significant threat to the country’s banking sector.

Among the recent discoveries, PixBankBot has emerged as a new variant that specifically targets online services of Brazilian bank, especially Pix.

PixBankBot: How it works

The PixBankBot malware disguises itself as a PDF application, utilizing the icon and name of a genuine PDF app to deceive victims into installing the malicious software.

Once installed, the malware prompts users to enable the Accessibility Service, which it then abuses for keylogging and executing the ATS framework.

PixBankBot
Malware prompts for Accessibility Service – CRIL

Upon enabling the Accessibility Service, the malware secretly sends basic device information such as device name, Android version, IP address, and region to a Command & Control (C&C) server.

The PixBankBot trojan utilizes the Accessibility Service to identify the package name of the targeted banking application.

If the victim interacts with any of the banking applications listed in the provided table, the malware initiates keylogging and begins executing the ATS.

To further mask its activities, PixBankBot creates a fake window on a genuine banking application, ensuring the victim remains unaware of the malicious actions taking place in the background.

Meanwhile, the malware interacts with the legitimate banking application to carry out automatic fund transfers.

PixBankBot: Cashing in on transfers

Fund transfers are facilitated through Pix keys, which serve as unique identifiers associated with recipients’ bank account information. The malware connects to a Pastebin URL to retrieve the Threat Actors’ (TA’s) Pix key.

Each targeted banking application receives different system-generated unique keys (UUID) encoded in base46, enabling the malware to execute fund transfers.

To insert the fetched Pix key, the malware scans for UI elements containing the word “chave” (which means “key” in Portuguese).

Once located, the malware inserts the Pix key into the corresponding edit text field, obtained from the server.

The specific code demonstrated in the report is designed for the ITAU bank, although the malware scans different UI elements to find the page related to the Pix key in other targeted banking applications.

“Once the malware finishes the money transfer, it sends the transfer amount and the targeted bank name to the C&C server. Then it removes itself from the infected device to avoid being detected,” said the report.

“The TA(s) behind PixBot has skillfully monitored all the UI elements of the targeted banking application to implement an ATS framework and conduct fraudulent transactions on the victim’s device,” it added.

Moreover, the threat actor (TA) has implemented additional measures to uninstall the malicious application from the compromised device in certain situations.

For example, if the account balance dips below R$500.00 or if a money transfer has been executed successfully, the application automatically deletes itself to evade detection and prevent the victim from becoming suspicious.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Previous Post

ALPHV Ransomware Group Hits BC Attorney: What’s With Law Firms and Cybersecurity?

Next Post

‘SentinelOne, ESET, Kaspersky’: Peddlers Claim to Sell AV and EDR Killers That Evade All Detection

Next Post
AV and EDR Killers

'SentinelOne, ESET, Kaspersky': Peddlers Claim to Sell AV and EDR Killers That Evade All Detection

Upcoming Webinar

Threat Landscape Reports 2025

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups
Cyber News

CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups

February 4, 2026
Ransomware Attacks 2026
Cyber News

Ransomware Attacks Have Soared 30% in Recent Months

February 4, 2026
Flock Safety ALPR cameras
Cyber News

Mountain View Shuts Down Flock Safety ALPR Cameras After Year-Long Unrestricted Data Access

February 4, 2026
Lakelands Public Health cyberattack
Firewall Daily

Lakelands Public Health Confirms Cyberattack, Says Sensitive Data Unaffected

February 4, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information