s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-apk.pixpirate

📛 Threat Title

Malware family: PixPirate

Category: PixPirate First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `apk.pixpirate`. Printable name: PixPirate.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain apk.pixpirate VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/apk.pixpirate

IOC database

Type
domain
Value
apk.pixpirate
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-apk.pixpirate

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/apk.pixpirate

References (1)

Remediations (10)

  • web:cisotimes.com

    Working of PixPirate PixPirate is the most recent generation of Android banking trojans that can use the Automatic Transfer System (ATS) to execute malicious money transfers over the Pix platform. It disguises itself as a trusted application while delivering its harmful payload behind well-known names and icons. The malware uses a dropper application to download and install itself, immediately ...

  • web:cybersecuritynews.com

    The malware known as " PixPirate ," which Cleafy discovered between the end of 2022 and the beginning of 2023, is the most recent generation of Android banking trojans that can use the ATS (Automatic Transfer System).

  • web:github.com

    Android - Remote Access Trojan List. Contribute to wishihab/Android-RATList development by creating an account on GitHub.

  • web:heimdalsecurity.com

    A new strain of mobile malware targeting Brazil and other LATAM nations has just been discovered. The malware is designed to steal sensitive data and commit fraud against Pix platform users. This most recent generation of Android banking trojans, known as PixPirate , discovered by Cleafy between late 2022 and the beginning of 2023, allows attackers to automatically insert a malicious money ...

  • web:homesec.ai

    PixPirate is a sophisticated financial remote access trojan (RAT) malware that heavily utilizes anti-research techniques. This malware's infection vector is based on two malicious apps: a downloader and a droppee. Operating together, these two apps communicate with each other to execute the fraud. So far, IBM Trusteer researchers have observed this malware attacking banks in Brazil.

  • web:thehackernews.com

    The threat actors behind the PixPirate Android banking trojan are leveraging a new trick to evade detection on compromised devices and harvest sensitive information from users in Brazil. The approach allows it to hide the malicious app's icon from the home screen of the victim's device, IBM said in a technical report published today. "Thanks to this new technique, during PixPirate ...

  • web:www.appdome.com

    How Appdome Protects Against PixPirate Trojan in Android Apps? Appdome's dynamic Detect PixPirate Trojan plugin for Android combines advanced protections for preventing malware injections and runtime attacks. It prevents accessibility service abuse, malicious keylogging, and overlay attacks.

  • web:www.darkreading.com

    'PixPirate' RAT Invisibly Triggers Wire Transfers From Android Devices A multitooled Trojan cuts apart Brazil's premier wire transfer app. Could similar malware do the same to Venmo, Zelle, or PayPal?

  • web:www.forbes.com

    This particular malware , dubbed PixPirate and first spotted by Cleafy earlier this year, has now been further analyzed by IBM's research team.

  • web:www.wizcase.com

    During this activity, PixPirate uses an overlay to hide its operations from the user, ensuring the victim remains unaware. Security Intelligence notes that PixPirate employs sophisticated methods, including remote access, SMS interception, and anti-removal capabilities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.