TF-MAL-apk.pixpirate
📛 Threat Title
Malware family: PixPirate
Description
ThreatFox malware family `apk.pixpirate`. Printable name: PixPirate.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
apk.pixpirate
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/apk.pixpirate
IOC database
- Type
- domain
- Value
apk.pixpirate- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-apk.pixpirate
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/apk.pixpirate
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cisotimes.com
Working of PixPirate PixPirate is the most recent generation of Android banking trojans that can use the Automatic Transfer System (ATS) to execute malicious money transfers over the Pix platform. It disguises itself as a trusted application while delivering its harmful payload behind well-known names and icons. The malware uses a dropper application to download and install itself, immediately ...
-
web:cybersecuritynews.com
The malware known as " PixPirate ," which Cleafy discovered between the end of 2022 and the beginning of 2023, is the most recent generation of Android banking trojans that can use the ATS (Automatic Transfer System).
-
web:github.com
Android - Remote Access Trojan List. Contribute to wishihab/Android-RATList development by creating an account on GitHub.
-
web:heimdalsecurity.com
A new strain of mobile malware targeting Brazil and other LATAM nations has just been discovered. The malware is designed to steal sensitive data and commit fraud against Pix platform users. This most recent generation of Android banking trojans, known as PixPirate , discovered by Cleafy between late 2022 and the beginning of 2023, allows attackers to automatically insert a malicious money ...
-
web:homesec.ai
PixPirate is a sophisticated financial remote access trojan (RAT) malware that heavily utilizes anti-research techniques. This malware's infection vector is based on two malicious apps: a downloader and a droppee. Operating together, these two apps communicate with each other to execute the fraud. So far, IBM Trusteer researchers have observed this malware attacking banks in Brazil.
-
web:thehackernews.com
The threat actors behind the PixPirate Android banking trojan are leveraging a new trick to evade detection on compromised devices and harvest sensitive information from users in Brazil. The approach allows it to hide the malicious app's icon from the home screen of the victim's device, IBM said in a technical report published today. "Thanks to this new technique, during PixPirate ...
-
web:www.appdome.com
How Appdome Protects Against PixPirate Trojan in Android Apps? Appdome's dynamic Detect PixPirate Trojan plugin for Android combines advanced protections for preventing malware injections and runtime attacks. It prevents accessibility service abuse, malicious keylogging, and overlay attacks.
-
web:www.darkreading.com
'PixPirate' RAT Invisibly Triggers Wire Transfers From Android Devices A multitooled Trojan cuts apart Brazil's premier wire transfer app. Could similar malware do the same to Venmo, Zelle, or PayPal?
-
web:www.forbes.com
This particular malware , dubbed PixPirate and first spotted by Cleafy earlier this year, has now been further analyzed by IBM's research team.
-
web:www.wizcase.com
During this activity, PixPirate uses an overlay to hide its operations from the user, ensuring the victim remains unaware. Security Intelligence notes that PixPirate employs sophisticated methods, including remote access, SMS interception, and anti-removal capabilities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.