Prilex is a Brazilian cybercriminal threat actor and associated malware family focused on financial fraud against payment ecosystems. Active since at least 2014, the group first became known for ATM jackpotting operations in Brazil and later evolved into a modular point-of-sale malware operation targeting payment terminals and EFT/TEF environments. Prilex has been linked to large-scale ATM compromise, payment card data theft, and the cloning and fraudulent use of EMV chip-and-PIN cards. In its ATM phase, Prilex compromised bank environments, conducted internal reconnaissance, used default credentials for lateral movement, and deployed malware that patched legitimate ATM software to enable jackpotting. The malware also captured payment card data from cards used in infected machines. In its later PoS-focused phase, Prilex shifted to highly targeted intrusions rather than broad spam distribution, commonly relying on social engineering, including impersonation of technicians and abuse of remote-access software to gain entry and install malware. Prilex PoS malware targets Brazilian payment software and has progressed from software patching and memory scraping to more advanced interception of live payment flows. Observed capabilities include patching PoS components, hooking Windows APIs, intercepting communications between PoS software and PIN pads over serial interfaces, modifying transaction content in real time, and storing stolen transaction data in encrypted form prior to exfiltration. Recent variants have used a modular architecture with backdoor, stealer, and uploader components. A defining aspect of Prilex operations is abuse of weaknesses in EMV transaction implementations. Earlier activity used replay-style techniques, while later variants adopted so-called GHOST transactions that capture live transaction data and obtain fresh EMV cryptograms from victim cards for fraudulent purchases. Separate reporting has also tied Prilex to a card-cloning ecosystem that included malware on infected PoS terminals, a malicious Java applet for smart cards, and tooling used to write stolen payment data onto cards and facilitate fraudulent withdrawals and purchases. This tradecraft enabled bypass of optional EMV authentication and cardholder-verification steps in certain configurations, allowing cloned cards to be accepted without normal validation. Prilex is best characterized as a financially motivated Brazilian cybercriminal actor specializing in payment fraud, card theft, and post-compromise manipulation of payment transactions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazilian financially motivated threat actor operating since 2014, evolving from ATM jackpotting and card cloning to modular PoS malware campaigns targeting the payment industry and conducting EMV fraud including replay and 'GHOST' transactions.
Brazilian cybercriminal group conducting ATM jackpotting and POS malware operations to steal payment card data and enable cloning of chip-and-PIN cards via a broader card-fraud-as-a-service infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.