Zimperium’s zLabs threat intelligence team has identified PixRevolution, a sophisticated Android banking trojan designed to hijack Brazil’s PIX instant payment system in real time.
The malware marks a new phase in mobile financial fraud by combining screen surveillance with operator-driven attacks that intervene during live transactions.
Unlike traditional banking trojans that rely on automated overlays or credential harvesting, PixRevolution allows a human or AI operator to watch an infected device’s screen as a payment occurs. When a victim initiates a PIX transfer the malware waits until the final confirmation stage before quietly modifying the recipient’s PIX key.
To the user the process appears normal. A brief loading screen appears while the malware replaces the intended recipient with an attacker-controlled account. The transaction then completes successfully but the funds are redirected instantly to the criminal.
The malware is typically distributed through fraudulent app store pages that mimic legitimate services. Victims are persuaded to install a malicious Android application which then requests accessibility permissions under the pretense of enabling functionality. In reality these permissions provide full visibility into on-screen activity and allow the trojan to manipulate user input.
PixRevolution also streams the victim’s screen to a remote command and control server using Android’s MediaProjection API. This enables attackers to monitor financial activity live and inject commands that alter payment details seconds before confirmation.
Researchers warn the model could expand beyond Brazil as instant payment platforms grow worldwide. Security teams should monitor mobile threats targeting accessibility services and real time payment workflows closely.

