Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets

Cybersecurity researchers have identified six new Android malware families capable of stealing sensitive data and conducting financial fraud through advanced techniques like real-time screen hijacking and automated permission bypass.
Cybersecurity researchers have discovered half-a-dozen new Android malware families that come with capabilities to steal data from compromised devices and conduct financial fraud.
The Android malware range from traditional banking trojans like PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and Oblivion RAT to full-fledged remote administration tools such as SURXRAT.
PixRevolution, according to Zimperium, targets Brazil's Pix instant payment platform, hijacking victims' money transfers in real-time to route them to the threat actors instead of the intended payee. "This new strain of malware operates stealthily within the device until the moment the victim initiates a Pix transfer," security researcher Aazim Yaswant said. "What distinguishes this threat from conventional banking trojans is its fundamental design: a human or AI agent operator is actively engaged on the remote end, observing the victim's phone screen instantaneously, poised to act at the precise moment of transaction."
Brazilian users have also become the target of another Android‑based malware campaign called BeatBanker, which spreads primarily through phishing attacks. BeatBanker uses an unusual persistence mechanism involving playing an almost inaudible 5-second audio file on a loop to prevent termination. It creates overlay pages for Binance and Trust Wallet to replace destination addresses with the attacker's address during USDT transactions.
TaxiSpy RAT abuses Android's accessibility service and MediaProjection APIs to collect sensitive data and target Russian banking and crypto apps. Meanwhile, new Malware-as-a-Service (MaaS) offerings like Mirax and Oblivion RAT are being sold on dark web forums. Oblivion RAT is particularly notable for its automated permission-granting mechanism that bypasses security features on devices from major manufacturers like Samsung, Xiaomi, and OPPO without user interaction.
Another commercially distributed malware, SURXRAT, managed by Indonesian threat actors, uses Firebase-based infrastructure for persistent control. The integration of large language model (LLM) components in some of these new samples indicates that threat actors are increasingly leveraging AI to enhance their malicious capabilities.
Source: The Hacker News















