Gopix: banking trojan bypasses trust through familiar apps

The illusion of security is a dangerous thing, and a newly discovered banking trojan, GoPix, is exploiting that very vulnerability. While cybersecurity professionals routinely warn against zero-risk, most users relax their vigilance when engaging with trusted applications. This threat, however, demonstrates the peril of complacency, leveraging the ubiquity of platforms like WhatsApp and Google Chrome to distribute a sophisticated malware campaign.

A brazilian origin, global reach

A brazilian origin, global reach

Originating in Brazil, GoPix has been operating for three years, attempting to infect over 90,000 individuals globally (as of March 2026, according to Kaspersky). What sets this malware apart isn’t just its technical complexity, but its ingenious distribution method. It utilizes Proxy AutoConfig (PAC) files—elements that operate solely in device memory—to facilitate man-in-the-middle attacks and malvertising.

The attackers aren’t relying on brute force. Instead, they're deploying targeted campaigns through Google Ads, serving malicious advertisements to users of WhatsApp, Google Chrome, and even the Brazilian postal service. The links within these ads lead directly to the GoPix website. The setup itself is unremarkable, but the precision targeting is stunning. GoPix doesn’t indiscriminately infect devices. Instead, it analyzes each user’s IP address to determine if they’re a potential victim – or merely bots used by cybersecurity firms.

This tiered approach, releasing the trojan only to verified targets, has significantly hampered detection efforts. It mirrors the tactics employed in advanced persistent threats (APTs), typically associated with nation-state actors and sophisticated hacking groups. The goal? Simple: financial theft. GoPix identifies bank transfers and cryptocurrency transactions, then bypasses existing security measures to siphon funds directly to the attackers.

Kaspersky’s analysis reveals a chilling level of sophistication. The malware doesn’t simply intercept credentials; it actively evades detection, operating silently in the background while transferring illicit gains. The scale of potential financial losses is significant, and the trojan’s ability to remain undetected poses a serious challenge to both individuals and financial institutions.

The rise of GoPix serves as a stark reminder that even the most familiar digital spaces can harbor hidden dangers. It’s a lesson in vigilance: trust, but verify, and never assume that a trusted app equates to absolute security. The battle for online financial safety is far from over, and this latest threat underscores the need for constant adaptation and heightened awareness.

n ,n