Two recently discovered malicious Android applications have been used to target users of Brazil’s immediate payment ecosystem in an apparent attempt to deceive victims into fraudulently transferring their whole account balances into a bank account under attackers’ control.
When a user launches their PIX bank app, Pixstealer displays an overlay window in which the victim cannot see the attacker’s movements. Behind the window, the attacker retrieves the available funds and transfers them to another account, typically the whole account balance.