Zimperium zLabs Uncovers PixRevolution Android Trojan Hijacking Brazil’s PIX Payments in Real Time

Zimperium announced new research from its zLabs threat intelligence team uncovering PixRevolution, a sophisticated Android banking trojan designed to hijack Brazil’s widely used PIX instant payment system in real time.

PixRevolution represents a significant evolution in mobile financial malware. Unlike traditional banking trojans that rely heavily on automated overlays or credential theft, PixRevolution introduces an agent-operated attack model in which a human or AI operator monitors an infected device’s screen live and intervenes at the precise moment a victim initiates a PIX transfer.

Once installed, the malware silently waits until a user begins a transaction. When the victim enters the payment details and confirms the transfer, PixRevolution briefly displays a loading screen while secretly replacing the recipient’s PIX key with one controlled by the attacker. The transaction then completes normally from the user’s perspective — but the funds are instantly redirected to the attacker’s account.

“PixRevolution highlights how mobile financial malware is evolving toward real-time, operator-driven attacks,” said Nicolás Chiaraviglio, Chief Scientist at Zimperium. “Instead of relying solely on automated scripts, attackers are now leveraging live device visibility to intervene at exactly the right moment. This approach allows the malware to bypass many traditional detection methods and makes instant payment systems an especially attractive target.”

The malware spreads through fake app store pages designed to mimic legitimate listings, tricking users into downloading malicious Android applications disguised as trusted services. Once installed, the app requests accessibility permissions under the guise of enabling functionality. In reality, this permission grants the trojan full visibility into on-screen activity and allows it to manipulate user interactions.

PixRevolution also captures and streams the victim’s screen to a remote command-and-control server using Android’s MediaProjection API. This enables attackers to monitor financial activity in real time and inject commands that overwrite transaction details moments before the payment is confirmed.

The threat is particularly concerning given the scale of the PIX ecosystem. Launched by Brazil’s central bank in 2020, PIX now processes billions of transactions each month and is used by the majority of the country’s population. Because PIX transfers are instant and irreversible, fraudulent transactions are extremely difficult to recover once completed.

Zimperium researchers warn that the operational model behind PixRevolution, combining screen surveillance, accessibility abuse, and operator-controlled transaction manipulation, could easily extend beyond Brazil to other global instant payment systems.

Articles similaires

Malware Update

19 August 2026

Zimperium zLabs Uncovers ToxicPanda 2.0, a Significantly More Powerful Android Banking Trojan

News Highlights : • Malware expands targeting to 349 banking, financial, e-wallet, and (…)

Malware Update

19 March 2026

New Zimperium Report Finds Banking Malware Expands Global Reach, Targeting 1,200+ Financial Apps

New Zimperium, the world leader in AI-empowered mobile security, today Report Finds Banking (…)

Malware Update

17 March 2026

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools