PULSE NAME
GoPix banking Trojan targeting Brazilian financial institutions
WHITE GoPix AlienVault 2026-03-16 Modified: 2026-03-16
26
IOCs
MEDIUM VOLUME
GoPix is an advanced persistent threat targeting Brazilian financial institutions and cryptocurrency users. It uses memory-only implants and obfuscated PowerShell scripts, evolving from previous RAT and ATS threats. The malware employs sophisticated techniques, including malvertising via Google Ads, man-in-the-middle attacks, and monitoring of Pix transactions and Boleto slips. GoPix bypasses security measures, maintains persistence, and uses robust cleanup mechanisms. It leverages multiple obfuscation layers and a stolen code signing certificate to evade detection. The threat actors carefully select victims, including financial bodies of state governments and large corporations, using legitimate anti-fraud services for targeted delivery.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GoPix
Indicators of Compromise (3 / 26 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 28c314acc587f1ea5c5666e935db716c 2026-03-16
FileHash-MD5 d3a17cb4cdba724a0021f5076b33a103 2026-03-16
FileHash-MD5 eb0b4e35a2ba442821e28d617dd2daa2 2026-03-16