Security researchers reported new banking malware campaigns targeting Brazilian users and financial institutions, with one operation focused on Android devices and Brazil's Pix instant payment ecosystem, and another aimed at Windows users of at least 33 Brazilian banks. The Android trojan, dubbed PixRevolution, was identified by Zimperium as malware built to hijack mobile payments in real time, using a human operator to intervene at the moment of transaction and redirect funds. The campaign reflects the continued attractiveness of Brazil's heavily used digital payment environment to financially motivated attackers.
A separate but related report described VENON, a Rust-based Windows banking trojan disclosed by ZenoX that uses banking overlays, active window monitoring, and LNK hijacking techniques associated with Latin American banking malware. Researchers said VENON is delivered through a multi-stage infection chain involving DLL side-loading, likely social engineering, and a PowerShell-based downloader, then applies anti-analysis measures such as AMSI bypass, ETW bypass, anti-sandbox checks, and indirect syscalls before contacting cloud infrastructure. One additional reference about malicious Rust crates targeting developer secrets is not part of the same event, as it concerns software supply chain theft rather than banking malware aimed at Brazilian financial users.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed a new Android banking trojan dubbed PixRevolution that targets Brazil's Pix instant payment system. The malware is spread via fake Google Play pages, abuses an accessibility service for device control, and enables operators to hijack transfers in real time by showing a fake wait overlay while redirecting funds.
Researchers reported a new Rust-based banking malware family called VENON targeting users in Brazil, marking a shift from the region's more common Delphi-based banking trojans. The malware was described as targeting 33 banks and digital asset platforms through a multi-stage DLL side-loading chain, banking overlays, shortcut hijacking, and multiple evasion techniques.
An earlier sample of the Rust-based Windows banking malware later named VENON was dated January 2026. Researchers noted developer path references to the username "byst4" and assessed the code structure may indicate AI-assisted development.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.