Brazil's aPIXcalypse
Anchises Moraes (Threat Intel Lead · Apura)
Payment Village @ DEF CON 33 · Day 1 · Payment Village
Overview
Anchises Moraes, Threat Intel Lead at the Brazilian cybersecurity firm Apura, delivered a compelling talk at Payment Village titled "Brazil's aPIXcalypse," shedding light on the transformative yet perilous journey of Brazil's real-time payment system, Pix. Launched just five years ago in 2020, Pix has rapidly become the cornerstone of financial transactions in one of the world's largest economies, boasting over 200 million citizens. While lauded for its efficiency and widespread adoption, Pix has also inadvertently created a perfect storm for cybercriminals and traditional fraudsters, forcing a paradigm shift in how financial institutions and individuals approach security.

Brazil's aPIXcalypse
Speakers: Anchises Moraes, Threat Intel Lead, Apura
Conference: Payment Village
YouTube: https://www.youtube.com/watch?v=qDB3vDaH_U8
Overview
Anchises Moraes, Threat Intel Lead at the Brazilian cybersecurity firm Apura, delivered a compelling talk at Payment Village titled "Brazil's aPIXcalypse," shedding light on the transformative yet perilous journey of Brazil's real-time payment system, Pix. Launched just five years ago in 2020, Pix has rapidly become the cornerstone of financial transactions in one of the world's largest economies, boasting over 200 million citizens. While lauded for its efficiency and widespread adoption, Pix has also inadvertently created a perfect storm for cybercriminals and traditional fraudsters, forcing a paradigm shift in how financial institutions and individuals approach security.
Moraes' presentation delves into the intricate technical underpinnings of Pix, its unprecedented adoption rates, and the subsequent "waves" of sophisticated criminal exploitation. He meticulously details how a technologically robust system, designed with best-in-class security protocols, can still become a formidable challenge when confronted with human vulnerabilities, social engineering, and an agile criminal ecosystem. The talk serves as a critical case study for other nations, including the United States with its nascent FedNow system, on the profound implications of instant payment systems for both economic inclusion and cybersecurity.
The core message is a stark warning: the convenience and speed that make real-time payment systems so popular are precisely what criminals exploit to their advantage, making fraud detection and fund recovery exponentially harder. Moraes highlights that while the Pix protocol itself has no known fundamental technical vulnerabilities, the real battle lies in securing the endpoints (mobile devices), educating users against social engineering, and adapting financial fraud prevention strategies to an "always-on," instant transaction environment. This article will explore these challenges, the specific tactics employed by fraudsters, and the defensive measures being implemented, offering valuable insights for the global financial security community.
Background
Brazil's journey into real-time payments is rooted in a long history of advanced digital banking. As one of the first countries globally to adopt internet banking in the 1990s, Brazil has also been a hotbed for sophisticated cybercrime, particularly in banking Trojans and mobile banking intrusions. Against this backdrop, the Brazilian Central Bank (BCB) embarked on a decade-long project to develop Pix, launching it in November 2020. The system was designed to replace slower, traditional electronic transfer methods like TED, which could take hours or even days to clear and were limited to business hours.
The technical architecture of Pix is robust. All Brazilian banks are interconnected via the Rede do Sistema Financeiro Nacional (RSFN), a secure virtual network akin to the international SWIFT network. The BCB maintains a central directory called SPI (Sistema de Pagamentos Instantâneos), which maps unique identifiers, known as Pix keys or Pix aliases, to bank account information. These keys can be an individual's email, phone number, national ID (CPF), or a random string, making transactions as simple as knowing a recipient's phone number. The underlying protocol itself incorporates strong security measures, including ubiquitous encryption, digital signatures, JWT (JSON Web Tokens) for message content integrity, and SSL VPNs for secure communication, leading Moraes to conclude that "there is no actually technical vulnerability that has been exploited as far as we know in general."
The adoption of Pix has been nothing short of phenomenal. Within five years, it has become the dominant payment method in Brazil, accounting for 76% of all payments, surpassing cash (68%), credit cards (51%), and debit cards (32%). This rapid uptake was partly accelerated by the COVID-19 pandemic, which pushed more people towards digital transactions. Crucially, Pix has significantly increased financial inclusion, bringing a large segment of the previously unbanked population into the formal financial system, with Moraes estimating that almost 100% of Brazilians now have bank accounts and Pix keys. This widespread adoption, however, also expanded the attack surface, creating new opportunities for criminals who quickly adapted to the system's instant nature.
Key Findings
Moraes' talk highlights that while the core Pix protocol is technically sound, its real-time, 24/7 nature, coupled with human factors and specific implementation details, has created a fertile ground for diverse and evolving criminal activities. The key findings reveal a multi-faceted threat landscape:
- Exploitation of Speed for Money Laundering: The instantaneity of Pix transactions is a double-edged sword. Criminals can rapidly transfer stolen funds across multiple money mill accounts within seconds, making forensic tracing and fund recovery by banks exceedingly difficult. As Moraes notes, by the time a bank investigates the first hop, the money has often already been moved, leaving the victim with "no money to give back."
- 24/7 Crime Operations: The ability to transact around the clock means criminals can now operate at any time, day or night. This necessitates that banks maintain 24/7 security and fraud prevention teams and develop real-time fraud detection systems capable of making instantaneous decisions, a significant shift from traditional systems that had hours or days for investigation.
- Waves of Social Engineering Attacks:
- First Wave (Phishing): Early attacks focused on tricking users into registering their Pix keys on fraudulent websites via SMS or email, often under the guise of "enabling" Pix.
- Second Wave (Exploiting/Faking Bugs): Initially, some specific bank implementations of Pix had bugs (e.g., a double-spending flaw in overnight transactions). While rare and mostly patched, criminals quickly fabricated similar "magic investment" schemes, convincing victims to send money to a "special" Pix key that promised double returns, but instead just sent money directly to the fraudster.
- Third Wave (Investment Scams): Persistent and widespread, these scams promise exorbitant returns based on fake crypto or AI investments. Often promoted through hacked social media profiles of celebrities with millions of followers, these schemes prey on greed, sometimes even offering small initial returns to build trust before a large-scale theft.
- Physical Mobile Phone Theft: A pervasive and dangerous threat, criminals actively target individuals on the streets to steal unlocked mobile phones. The goal is not the device itself, but access to banking apps to drain accounts via Pix. Moraes recounts personal experiences and incidents involving high-profile figures, emphasizing the brazenness and speed of these attacks, especially in traffic jams.
- Professional Money Mill Account Industry: Brazil has seen the rise of dedicated "muleados" – professionals who specialize in creating and seasoning fake bank accounts using forged IDs. These accounts are then sold on criminal forums for money laundering. Additionally, impoverished individuals are coerced or paid small sums to rent out their legitimate bank accounts, making fraud detection even harder as these appear to be "real users" with "real bank accounts."
- Ineffectiveness of Fund Recovery Mechanisms: The Brazilian Central Bank introduced the Special Mechanism of Return of Money (MEG) to help victims recover funds. However, due to the rapid movement of money across multiple accounts, Moraes states that in practical terms, it "helps nothing" and victims "will never see your money again" in most cases.
- Sophisticated Fake Call Centers and SMS Scams: Fraudsters operate professional call centers that mimic legitimate bank operations, complete with waiting lines and background noise. They send convincing SMS messages about fake Pix transactions, prompting victims to call these fraudulent centers where they are socially engineered into installing malware or making "cancellation" transfers directly to criminal accounts. Moraes notes these are "paid jobs" in Brazil, unlike human trafficking rings seen in other regions.
- Pix Malware: A significant technical threat, specialized mobile banking Trojans (e.g., Pix Stealer, Brass King, Pix Parade, BrasDex, GoToRat, Pix Banking Bot, Go Pigs) specifically target Android devices. These malware families exploit Android's accessibility services feature, designed for users with disabilities, to gain extensive control over the device interface. This allows them to overlay fake screens, perform actions on behalf of the user, and bypass multi-factor authentication (MFA).
- "Return Fraud" and Merchant Scams: A newer trick involves criminals sending a Pix payment, then immediately claiming it was a mistake and asking the victim to send the money back to a different account. The criminal then disputes the original transaction with their bank, getting their money back while the victim has sent money to a third party. A variation involves buying goods, paying via Pix, taking the item, and then disputing the payment as fraudulent, leaving the seller with no product and no money.
- Large-Scale Core Banking Attacks: While not a Pix vulnerability per se, Moraes highlights a recent incident where a highly skilled criminal group exploited a technology provider's core banking system by purchasing a junior developer's credentials for $1,000-$2,000. They injected fake transactions, stealing over $300 million (with one bank publicly reporting $150 million) over eight hours, using Pix to quickly launder the funds. This echoes sophisticated attacks like those by the Lazarus Group.
Technical Deep Dive
The technical security of the Pix system itself is a point of pride for the Brazilian Central Bank. The Pix Protocol is built on a foundation of robust cryptographic and network security measures. All interbank communications are routed through the Rede do Sistema Financeiro Nacional (RSFN), a dedicated virtual private network that ensures secure and isolated data exchange between financial institutions, conceptually similar to how the SWIFT network operates globally.
Transactions within Pix are fortified with end-to-end encryption, ensuring data confidentiality as it traverses the network. Each transaction is also digitally signed, providing integrity and non-repudiation, meaning the sender cannot later deny initiating the payment. Furthermore, the content of payment messages utilizes JWT (JSON Web Tokens), which are self-contained, digitally signed, and often encrypted, offering an additional layer of security for the transaction details. The entire communication infrastructure is protected by SSL VPNs, establishing secure tunnels for data transmission. This comprehensive approach means that direct exploitation of the Pix protocol's underlying cryptography or messaging system is exceedingly rare. As Moraes emphasized, "the protocol itself has built in a very good security way. So we don't have too much vulnerabilities in general."
However, the ingenuity of Brazilian cybercriminals lies in bypassing these robust protocol-level defenses by targeting the weakest link: the end-user device and human psychology. A prime example is the sophisticated mobile banking malware prevalent in Brazil. These malware families, such as Pix Stealer, Brass King, Pix Parade, BrasDex, GoToRat, Pix Banking Bot, and Go Pigs, are predominantly designed for Android devices, leveraging social engineering to trick victims into downloading and installing malicious applications.
Once installed, these malware variants exploit a legitimate Android feature known as Accessibility Services. This feature, intended to assist users with disabilities by allowing applications to interact with the user interface (e.g., reading screen content, performing gestures), becomes a powerful weapon in the hands of attackers. The malware, granted these permissions, can:
- Monitor screen activity: Detect when a banking application is opened.
- Overlay fake screens: Present a fraudulent interface on top of the legitimate banking app. For instance, a user might see a fake "security update" screen while the malware operates in the background.
- Perform actions on behalf of the user: Once the user logs into their legitimate banking app, the malware, using Accessibility Services, can mimic user input to initiate and confirm Pix transfers to criminal money mill accounts without the user's direct knowledge or interaction.
- Bypass Multi-Factor Authentication (MFA): If a bank requires a biometric scan or PIN for transaction approval, the malware can display a fake prompt for "re-authentication" to complete the supposed "update," tricking the user into providing their biometric data or PIN, which then authorizes the fraudulent Pix transfer in the background.
A key characteristic of these malware families is their use of ATS (Automatic Transaction Systems). This means the malware is pre-configured with the destination Pix keys of criminal accounts. Upon detecting the user's banking app and successful login, the malware automatically initiates the transfer without requiring real-time remote control by a human operator, making the attacks faster and more scalable.
Beyond malware, the "return fraud" mechanism also demonstrates a clever exploitation of business logic and human trust. By initiating a legitimate Pix transfer and then disputing it after the victim has re-sent the money to a different account, criminals leverage the bank's fraud resolution process against the victim, effectively doubling their illicit gains or acquiring goods for free. This highlights how vulnerabilities in the broader financial ecosystem and human behavior, rather than the core Pix protocol, are the primary targets for sophisticated criminal enterprises.
Demo / Proof of Concept
While Anchises Moraes' presentation did not include a live technical demonstration or proof of concept of an exploit, it effectively used visual aids and recounted real-world scenarios to illustrate the various fraud mechanisms. Screenshots of phishing emails, criminal forum discussions about selling money mill accounts, and advertisements for fake investment schemes were shown to highlight the social engineering tactics. Moraes also referenced a video, which he noted could not be displayed in his PDF presentation, depicting the rapid nature of mobile phone theft in traffic jams in São Paulo, underscoring the physical threat vector. The talk's strength lay in its comprehensive cataloging of observed criminal activities and the detailed explanation of their operational mechanics, rather than a live exploit demonstration.
Defensive Implications
The "aPIXcalypse" scenario in Brazil offers critical lessons for financial institutions and users globally, especially as real-time payment systems like FedNow gain traction. The defensive implications are multi-layered, requiring significant shifts in strategy:
For Banks and Financial Institutions:
- Real-time Fraud Detection and Response: The most significant change is the necessity for real-time fraud detection systems. Traditional systems, which had hours or days to investigate suspicious transactions, are obsolete in an instant payment environment. Banks must now detect and decide on transactions within milliseconds, requiring advanced AI/ML models and automated response mechanisms. This also means increasing security staffing to provide 24/7 fraud prevention coverage.
- Stricter Transaction Limits: Brazilian banks have implemented rules like lower overnight transaction limits and a 24-hour delay for limit increases. This is a direct response to "flash kidnappings," where criminals abduct victims for a few hours to drain their accounts, and to prevent thieves from immediately maximizing stolen funds from a compromised phone.
- Geo-fencing and "Safe Places": Some banks have introduced "safe places" features, allowing users to define trusted locations (e.g., home, office). Transactions initiated outside these zones may have lower limits or even restrict access to sensitive information like investment portfolios, as Moraes personally experienced. This leverages GPS and IP address data for enhanced security context.
- Continuous User Awareness Campaigns: Given the prevalence of social engineering, banks are constantly running awareness campaigns via SMS, in-app messages, and even direct phone calls. These campaigns educate users about fake call centers, "return fraud," and investment scams, urging them to verify information directly with the bank and never transfer money to unknown accounts.
- Enhanced Account Opening Fraud Detection: To combat the money mill account industry, banks must strengthen their identity verification processes during account creation, leveraging advanced fraud analytics and potentially biometric verification to detect fake IDs and suspicious patterns.
- Insurance Coverage: Banks have responded by offering Pix fraud insurance to customers, covering losses incurred from phone theft or social engineering attacks that lead to unauthorized Pix transactions. While not a preventative measure, it addresses the financial consequences for victims.
For End-Users:
- Situational Awareness: Moraes' direct advice for anyone visiting Brazil is unequivocal: "Please don't use your phones on the streets." This applies even inside vehicles like Uber or taxis, as criminals are known to smash windows to steal phones.
- Strong Security Hygiene: Users must employ strong, unique passwords for their banking apps and phone unlock. Enabling biometric authentication (fingerprint, face ID) for phone unlock and app access is crucial.
- Extreme Skepticism of Unsolicited Communications: Treat any unexpected SMS, email, or phone call about banking transactions with extreme caution. Always verify by calling the official bank number (found on their website or card), not the number provided in the suspicious message.
- Beware of "Return Fraud": Never send money back to a different account if someone claims to have sent you Pix by mistake. If a legitimate error occurred, instruct the sender to contact their bank to initiate the official return mechanism (MEG).
- Verify QR Codes and Receipts: Always double-check the recipient details when scanning QR codes for payments, and do not trust digital receipts without independent verification, especially in merchant interactions.
- Caution with App Permissions: Be extremely cautious about downloading apps from unofficial sources and granting extensive permissions, particularly Accessibility Services, to unknown applications.
- Avoid "Too Good to Be True" Schemes: Recognize that investment opportunities promising unrealistic returns, especially those promoted through social media, are almost certainly scams.
In essence, the defensive posture against Pix-related fraud requires a holistic approach, integrating advanced technical controls, strict operational policies, continuous user education, and a heightened sense of personal vigilance. The Brazilian experience underscores that even the most secure payment protocols are vulnerable if the surrounding ecosystem and human elements are not adequately protected.
Key Takeaways
- Pix, while technically secure, has become a prime target for fraud due to its instant, 24/7 nature and widespread adoption. The core protocol is robust, but the surrounding ecosystem and human factors are heavily exploited.
- The speed of Pix transactions dramatically facilitates money laundering, making fund recovery extremely difficult for banks and victims. Funds can be moved across multiple money mill accounts in seconds, rendering traditional tracing mechanisms ineffective.
- Social engineering remains the most prevalent and effective attack vector, evolving through phishing, fake investment schemes, and sophisticated fake call centers. These tactics prey on human trust, fear, and greed, often leveraging compromised social media accounts.
- Physical mobile phone theft is a critical threat, with criminals targeting unlocked phones to access banking apps and drain accounts via Pix. This necessitates extreme user vigilance and bank-implemented geo-fencing and transaction limits.
- Sophisticated mobile banking malware, primarily on Android, exploits legitimate features like Accessibility Services to automate fraudulent Pix transactions. These malware families can bypass MFA and present fake screens to trick users into authorizing transfers.
- Defensive strategies must shift to real-time fraud detection, 24/7 security operations, and continuous, aggressive user awareness campaigns. Banks must implement stricter transaction controls and educate users to be highly skeptical of unsolicited banking communications.
About the Speaker(s)
Anchises Moraes is a highly respected figure in the Brazilian and international cybersecurity community. As a Threat Intel Lead at Apura, a Brazilian company with 13 years of experience in cyber threat intelligence (CTI) that has recently expanded globally with an office in Miami, Moraes brings deep expertise in understanding and countering cyber threats.
Beyond his corporate role, Moraes is a passionate advocate for the cybersecurity community. He is one of the founders of BSides São Paulo, a significant security conference in Brazil that drew 2,300 attendees this year. He also co-founded G.A.A Hacker Club in 2010, establishing Brazil's first hacker space. Furthermore, Moraes is a dedicated volunteer at WIN (Latin America Women for Cybersecurity), a community and NGO committed to fostering diversity in the industry by mentoring, training, and supporting women in cybersecurity. His extensive background in threat intelligence, community building, and advocacy positions him as a credible and insightful voice on the complex challenges posed by evolving financial technologies.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent threat-intel survey of Brazil's Pix fraud ecosystem with genuine regional expertise and good breadth of coverage. Solid Payment Village content — but it reads like a well-organized blog post more than a talk that needed to be live.
Heather Calloway (CISO) — SOLID
A well-documented threat intelligence briefing on Brazil's Pix fraud ecosystem that earns its place at Payment Village but doesn't reach beyond it. Moraes knows his material cold, and the case study has genuine relevance for institutions building or operating real-time payment systems — but the talk catalogues the problem more than it drives toward accountability or institutional action.