GoPIX Infostealer Targeting PIX Payment System in Brazil

GoPIX specifically targets the PIX payment system, which is popular in Brazil.

Context

On October 24, 2023, Kaspersky researchers released a report on several cyber threats, including the GoPIX infostealer malware campaign, which they assess has been active since December 2022.

Technical Details

According to Kaspersky:

“GoPIX is a typical clipboard stealer malware that steals PIX “transactions” used to identify payment requests and replaces them with a malicious (attacker controlled) one which is retrieved from the C2. The malware also supports substituting Bitcoin and Ethereum wallet addresses. However, these are hardcoded in the malware and not retrieved from the C2. GoPIX can also receive C2 commands, but these are only related to removing the malware from the machine.”

Community Impact

Retail, hospitality, and travel organizations conducting business operations in Brazil are encouraged to determine whether they leverage PIX as part of their operations and, if so to ingest the indicators of compromise (IOCs) included here, as well as taking other defensive measures such as reviewing activity records related to PIX transactions and scanning systems that interact with PIX.

IOCs

Kaspersky researchers provided the following IOCs:

Indicator

Type

EB0B4E35A2BA442821E28D617DD2DAA2

MD5

6BA5539762A71E542ECAC7CF59BDDF79

MD5

333A34BD2A7C6AAF298888F3EF02C186

MD5

More Recent Blog Posts