6 New Android Malware Families Are Draining Pix, Bank, and Crypto Accounts
Mar 12, 2026 // 12:32 - Lina Schonbein


Cybersecurity researchers have identified six new Android malware families PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, Oblivion RAT, and SURXRAT specifically designed to target banking apps, crypto wallets, and instant payment systems.

Identified Malware Families

According to reports from The Hacker News and Zimperium, these threats range from banking trojans to advanced remote administration tools:

  • PixRevolution: Targets Brazil’s Pix payment platform, hijacking transfers in real-time.
  • TaxiSpy RAT: A remote access tool that monitors device activity and steals sensitive data.
  • BeatBanker: Focused on harvesting banking credentials for unauthorized transactions.
  • Mirax: Infiltrates financial apps to exfiltrate user data.
  • Oblivion RAT: Gives attackers full remote control to facilitate financial theft.
  • SURXRAT: Allows for extensive data theft and device manipulation.

Key Tactics

These threats use sophisticated methods to bypass security:

  • Active Intervention: PixRevolution often involves a human or AI agent observing the victim’s screen to intervene during a transaction.
  • Clipboard Injection: They replace copied crypto wallet addresses with the attacker’s, redirecting funds.
  • Overlay Attacks: Fake login screens are placed over apps like PayPal or Google Pay to steal credentials.
  • OTP Bypassing: They intercept SMS messages in real-time to capture one-time passwords.

How to Protect Your Device

  • Stick to Official Stores: Only download apps from Google Play and avoid links in unsolicited messages.
  • Watch for Red Flags: Monitor for sudden battery drain or unexpected screen activity.
  • Use Better MFA: Prioritize authenticator apps or hardware keys over SMS-based codes.

#accounts  #and  #android  #are  #bank  #crypto  #draining  #families  #malware  #new  #news  #pix,   —   News