PULSE NAME
GoPix banking Trojan targeting Brazilian financial institutions
WHITE GoPix AlienVault 2026-03-16 Modified: 2026-03-16
26
IOCs
MEDIUM VOLUME
GoPix is an advanced persistent threat targeting Brazilian financial institutions and cryptocurrency users. It uses memory-only implants and obfuscated PowerShell scripts, evolving from previous RAT and ATS threats. The malware employs sophisticated techniques, including malvertising via Google Ads, man-in-the-middle attacks, and monitoring of Pix transactions and Boleto slips. GoPix bypasses security measures, maintains persistence, and uses robust cleanup mechanisms. It leverages multiple obfuscation layers and a stolen code signing certificate to evade detection. The threat actors carefully select victims, including financial bodies of state governments and large corporations, using legitimate anti-fraud services for targeted delivery.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
GoPix
Indicators of Compromise (3 / 26 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1b1f85b68e6c9fde709d975a186185c94c0faa51 2026-03-16
FileHash-SHA1 b7cfedf9346bc1a4f497396d35360c599663725d 2026-03-16
FileHash-SHA1 f110d0bd7f3bd1c7b276dc78154dd21eef953384 2026-03-16