The Brazilian threat group Prilex evolved from ATM jackpotting into a sophisticated point-of-sale malware operation that targeted Brazil’s payment ecosystem, compromising PoS terminals and EFT/TEF software to steal card data and manipulate EMV transactions. Early campaigns reportedly infected more than 1,000 ATMs at a Brazilian bank and were linked to cash theft and the cloning of more than 28,000 payment cards, while later operations focused on merchant environments by modifying PoS software, intercepting communications between terminals, PIN pads, and banks, and harvesting payment data in real time.
Researchers said Prilex developed techniques that undermined assumptions about the security of chip-and-PIN cards, including the use of a custom Java applet on smart cards to abuse optional EMV transaction steps so terminals could skip card authentication and accept any PIN. More recent variants moved beyond EMV replay to "GHOST transactions," capturing live transaction data and obtaining fresh EMV cryptograms from victim cards for fraudulent purchases. The operation was supported by a broader criminal toolkit that included the Daphne card-writing client, a stolen-card database, backdoor and stealer components, and targeted intrusion methods such as social engineering with fake technicians and remote-access tools like AnyDesk.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
According to Securelist, Prilex activity dropped off in 2021 after a highly active 2020. The lull was temporary before the group resurfaced with new variants.
Securelist reports that Prilex was highly active in 2020. This period preceded a quieter phase in 2021 and a later resurgence.
Securelist says Prilex claimed responsibility for a 2019 attack against a German bank. The incident allegedly caused losses of €1.5 million.
Securelist reports that the first Prilex point-of-sale malware samples were observed in the wild in October 2016. These early PoS attacks targeted Brazilian payment software and captured card data from merchant environments.
Securelist says Prilex changed its operational focus from ATM malware to point-of-sale systems in 2016. This marked the group's evolution toward targeting Brazilian payment ecosystems and EFT/TEF software.
During the 2016 carnival period, a Brazilian bank discovered that more than 1,000 of its ATMs had been infected and emptied in a jackpotting attack attributed to Prilex. The intrusion reportedly also enabled cloning of more than 28,000 payment cards used in those ATMs.
Securelist states that the Brazilian threat actor Prilex has been active since 2014. The same source says Brazilian cybercriminals had successfully launched EMV replay attacks since at least that year, techniques Prilex later adopted and evolved.
Securelist states that Prilex resurfaced in 2022 with three new malware variants. The 2022 branch also showed signs that its developers had started using Subversion for version control.
Researchers reported that Prilex had developed a method to steal payment card data from infected PoS terminals and clone EMV chip-and-PIN cards. The operation used modified PoS malware, a malicious Java applet on smart cards, and supporting tools including the Daphne card-writing client and a stolen-card database.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.