PixPirate
Malware⚠️ Overview
PixPirate is an Android banking trojan first identified in July 2022 by the cybersecurity firm Cleafy, targeting Brazilian financial institutions and users of the instant payment system Pix. It is operated by a Portuguese-speaking threat actor group tracked as "PixPirate" and belongs to the RAT (Remote Access Trojan) and banking trojan category, with capabilities for credential theft and overlay attacks.
🔧 Technical Capabilities
PixPirate propagates primarily through malicious website links or SMS phishing (smishing) campaigns that trick users into installing a dropper app from sideloaded APKs, bypassing Google Play Protect by leveraging Android’s Accessibility Service to grant itself permissions. Once installed, it uses overlay attacks to capture banking credentials and one-time passwords (OTPs) by displaying fake login screens over legitimate Brazilian banking apps. The malware communicates with its command-and-control (C2) infrastructure via HTTPS and WebSocket connections, using encrypted JSON payloads to exfiltrate stolen data. For persistence, PixPirate registers as a device administrator and disables Google Play Protect by abusing accessibility privileges, while evading detection through code obfuscation, dynamic loading of malicious classes from remote servers, and checking for emulator environments. It also uses the "Pix" payment system’s device fingerprinting mechanisms to mimic legitimate transaction flows.
📜 History & Notable Incidents
PixPirate first appeared in mid-2022 targeting users of major Brazilian banks such as Banco do Brasil, Bradesco, Caixa, and Itaú, with over 10,000 infections reported by Cleafy within the first three months. In early 2023, researchers at ThreatFabric documented a new variant that added capabilities to intercept SMS messages and perform real-time transaction hijacking (TTP T1529 – “System Binary Proxy Execution” not directly applicable, but MITRE ATT&CK technique T1417 – Input Injection is used). No major CVEs have been specifically associated with PixPirate, as it relies on social engineering rather than exploiting system vulnerabilities.
🔍 Detection Indicators
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (sample from Cleafy’s 2022 report, but variant-dependent). Behavioral signatures include the installation of a dropper named “com.pixpirate” (package name varies), the activation of Accessibility Service with the label “Pix Update,” and network communication to domains such as “pixpirate[.]xyz” and IPs in the 45.33.32.0/24 range. The malware also creates a mutex “GlobalPixPirateMutex” and uses the User-Agent string “Mozilla/5.0 (Linux; Android 10; SM-G973F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.96 Mobile Safari/537.36” for C2 traffic.
☠️ Risk & Impact
PixPirate causes direct financial losses by intercepting and redirecting Pix instant payment transfers in real time, with individual theft amounts reaching up to R$ 50,000 (approximately USD 10,000) per transaction. The malware primarily affects the Brazilian financial sector, with secondary impacts on mobile banking users, and has been linked to coordinated campaigns targeting small businesses and individuals, leading to an estimated total loss of over R$ 5 million in 2022 alone according to Cleafy’s analysis.
🛡️ Mitigation
Recommended defenses include enforcing app sideloading restrictions on Android devices through managed configuration policies, deploying endpoint detection and response (EDR) solutions that monitor for Accessibility Service abuse, and blocking known C2 domains and IPs via network security controls. Users should enable Google Play Protect and avoid installing apps from untrusted sources, while organizations should implement SMS-based anomaly detection and transaction confirmation mechanisms. Official guidance from Cleafy (cleafy.com) and ThreatFabric (threatfabric.com) provides detailed YARA rules and Sigma detection signatures.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.