Brazil malware swaps Pix QR codes in e-commerce
Kaspersky found 90 Brazilian stores infected with malware that replaces Pix QR codes and Pix Copia e Cola at checkout.
Kaspersky validated a finding attributed to independent researcher eremit4 about a campaign that quietly alters Pix QR Codes and the Pix Copia e Cola field on checkout pages at Brazilian e-commerce sites. The reported scope reaches 90 small and mid-sized stores, mostly built on Magento, with affected sectors including optical shops, auto parts, fashion and online fundraising sites. The core mechanism is checkout hijacking: shoppers see the legitimate page, but when they choose Pix, the code shown has already been replaced with one controlled by criminals, so the money ends up in accounts not linked to the store. Several reports also say the same malicious code can extend its reach to credit card data processed at checkout, bringing the case closer to classic skimming on the e-commerce site itself.
The case, in the notes reviewed, was not attributed to a named criminal group or a country of origin, and no hashes, domains or code samples were provided. TRBN did add one relevant technical detail, saying the campaign used six command-and-control domains to inject the malicious code into compromised sites. The coverage also stresses that the target is the e-commerce infrastructure, not customer devices, which multiplies the impact because it affects every shopper on an infected store without needing endpoint compromise.
On defense, the material converges on practical steps for merchants and consumers. For stores, Kaspersky advises keeping the platform updated, changing admin passwords, strengthening two-factor authentication and monitoring the site with security software. For users, the guidance is to avoid confirming Pix automatically after scanning a QR code, verify the recipient name, CNPJ and amount in the banking app, and distrust transfers to unknown individuals. If the transfer has already gone to the wrong recipient, the sources recommend contacting the bank or payment institution immediately, filing the incident and requesting the Special Return Mechanism, whose usage window was recently extended from 30 to 80 days by Brazil’s central bank, according to Procon-SP.
Executive summary
Kaspersky validated, based on a finding from an independent researcher identified as eremit4, a malware campaign that quietly alters Pix QR Codes and the Pix Copia e Cola field on checkout pages at Brazilian e-commerce sites. Public reporting puts the reach at 90 small and mid-sized stores, mostly built on Magento, with affected sectors including optical shops, auto parts, fashion and online fundraising sites.
The behavior described by the sources is consistent. A user reaches a legitimate payment page, selects Pix and, at that point, the code on screen has already been replaced by one controlled by criminals. The transaction ends up in accounts unrelated to the store, with no visible change in the interface, which makes real-time detection difficult. Several reports add that the same malicious code can also copy credit card data processed at checkout, expanding the case beyond Pix fraud into a skimming scenario on the merchant page itself.
According to the notes reviewed, the operation was not attributed to a named criminal group or a specific country. The operators are referred to generically as criminals or scammers. No technical IOCs were published in the journalistic pieces analyzed, except for one point from TRBN, which says the campaign uses six different command-and-control domains to inject the malicious code into compromised sites. That is enough to describe a web injection campaign rather than an endpoint fraud scheme.
From a defensive standpoint, the material converges on three lines. For merchants, keep the platform updated, change admin passwords, strengthen 2FA and monitor the site with security software. For consumers, verify the recipient name, CNPJ and amount in the banking app before authorizing Pix, and do not confirm the transaction automatically after scanning the QR code. If the diversion already happened, the sources recommend contacting the bank or payment institution immediately, filing the incident and activating the [Special Return Mechanism](https://sampi.net.br/jundiai/noticias/3004100/jundiai/2026/09/procon-orienta-consumidores-sobre-novo-golpe-em-compra-online), whose window was extended from 30 to 80 days by Brazil’s central bank, according to Procon-SP.
Context and background
The campaign appears at a time when Pix has already become a mass payment rail in Brazil and, for that reason, an attractive surface for checkout fraud. The novelty is not social engineering or obvious interface spoofing, but where the code is inserted. It is injected into the e-commerce site itself and triggered exactly when the user chooses to pay. The result is an almost invisible replacement of the QR Code and the copy-and-paste text.
According to Folha de S.Paulo, the public discovery happened on September 1, 2026 and was carried out by the independent researcher eremit4. The same coverage says the researcher described the threat as the new Brazilian magecart, a useful comparison because it places the case in the family of attacks that operate on legitimate payment pages to intercept value or sensitive data.
Kaspersky’s later validation turned an individual observation into a campaign with measurable reach. The figure of 90 infected stores is repeated by Folha de S.Paulo, UOL Tilt, Folha Vitória, Ground News and other reports, which suggests a solid journalistic consensus on the scale. Most affected sites would be small and mid-sized merchants, many on Magento, a detail that helps explain the homogeneity of the compromised surface.
At the same time, the reporting makes clear that the effect is not limited to Pix. Olhar Digital and the case video add that the same code can copy credit card data processed at checkout. That broader function points to malware designed around the purchase session, not only one payment method.
Key facts table
| Date | Event | Source | Confidence |
|---|---|---|---|
| 2026-09-01 | Independent researcher eremit4 discovers the malware that alters Pix in Brazilian e-commerce sites. | Folha de S.Paulo | confirmed |
| 2026-09-07 | Folha de S.Paulo reports that Kaspersky warned about a virus that swaps the Pix QR code for a fraudulent one at checkout. | Folha de S.Paulo | confirmed |
| 2026-09-07 | Folha de S.Paulo says Kaspersky validated the finding and detected 90 infected sites, mostly or all on Magento. | Folha de S.Paulo | confirmed |
| 2026-09-08 | O Tempo explains that the malware invades the payment page and alters the QR and Pix Copia e Cola to divert funds. | O Tempo | confirmed |
| 2026-09-08 | O Tempo publishes Kaspersky’s recommendations for merchants, including updates, passwords and 2FA. | O Tempo | confirmed |
| 2026-09-08 | Folha de S.Paulo recommends checking the recipient name, CNPJ and amount in the banking app before confirming Pix. | Folha de S.Paulo | confirmed |
| 2026-09-09 | UOL Tilt reports 90 affected e-commerce sites, mainly in optical goods, auto parts, fashion and online fundraising. | UOL Tilt | confirmed |
| 2026-09-09 | Olhar Digital adds that the malicious code can also copy credit card data. | Olhar Digital | confirmed |
| 2026-09-11 | TRBN says the campaign uses six command-and-control domains to inject the code. | TRBN | confirmed |
| 2026-09-11 | Procon-SP offers guidance on verifying data and using MED 2.0 after mistaken transfers. | Procon-SP / Sampi | confirmed |
| 2026-09-11 | Procon-SP says the MED deadline was extended from 30 to 80 days. | Procon-SP / Sampi | confirmed |
Operation timeline
| Date | Event | Actor/vector | Verified source |
|---|---|---|---|
| 2026-09-01 | Initial detection of the malware in Brazilian stores. | eremit4, checkout analysis | Folha de S.Paulo |
| 2026-09-07 | First report on discreet replacement of the Pix QR code. | Folha de S.Paulo, Kaspersky | Folha de S.Paulo |
| 2026-09-07 | Kaspersky validates the finding and estimates 90 compromised sites. | Kaspersky, e-commerce with Magento | Folha de S.Paulo |
| 2026-09-08 | Guidance is circulated for consumers and merchants. | O Tempo, Kaspersky | O Tempo |
| 2026-09-09 | New sector details and the extension to credit cards emerge. | UOL Tilt, Olhar Digital | UOL Tilt, Olhar Digital |
| 2026-09-11 | The six C2 domains detail is added. | TRBN, injection infrastructure | TRBN |
| 2026-09-11 | Procon-SP publishes response guidance and MED 2.0. | Procon-SP, consumer, bank | Procon-SP / Sampi |
Attack chain and TTPs
The chain described by the sources is an intrusion on the e-commerce site itself. In principle, this is not a compromise of the buyer’s device, but of the merchant’s payment page. When the customer selects Pix, the malicious script intervenes in the rendering of the QR Code and the Pix Copia e Cola field, replacing legitimate information with data controlled by the attacker.
That changes the detection problem. From the user’s perspective, the experience looks normal because the interface shows no visible changes. From the merchant’s perspective, the issue sits in the code loaded into the checkout, which in many cases is obfuscated, according to Folha de S.Paulo’s reference to a Kaspersky director. The report says the replacement is triggered by a strange piece of code, often written in obfuscated lines, which reinforces the hypothesis of frontend tampering or injection in the checkout script chain.
The same flow explains why a single compromised site can have broad impact. If a store receives many daily visits, each buyer is exposed at the exact moment of payment. TRBN sums it up well by saying the malware targets the e-commerce structure, not customer machines. The operational focus is the merchant’s server or web environment, not the user endpoint.
The sources also suggest a broader functional scope. Olhar Digital says the same code can copy credit card data processed at checkout. That fits a multipurpose skimming logic, where the attacker seeks value in different forms within the same payment page. The Magecart comparison made by eremit4 makes sense in that context, because it connects payment fraud and data capture.
| TTP | Description | Source |
|---|---|---|
| Checkout injection | The malicious code is inserted into the legitimate ecommerce payment page. | Folha de S.Paulo, TRBN |
| Pix QR manipulation | The QR Code shown to the user is replaced with one controlled by criminals. | UOL Tilt, O Tempo, O Povo |
| Pix Copia e Cola tampering | The copy-and-paste field or text is also modified before display. | Folha de S.Paulo, UOL Tilt, Folha Vitória |
| Obfuscation | Kaspersky describes a strange piece of code, often obfuscated. | Folha de S.Paulo |
| C2 infrastructure | TRBN reports six command-and-control domains. | TRBN |
| Card skimming | The same code can copy credit card data processed at checkout. | Olhar Digital, YouTube |
Regional impact
Regional overview
The case has broad regional coverage in Brazilian media, but the verifiable impact in the sources is concentrated in Brazil. The campaign affects small and mid-sized stores, with a compromise pattern that hits the checkout experience and, by extension, anyone paying with Pix from those sites.
The most solid regional reading is operational, not geopolitical. There is no state attribution or public evidence of spread to other countries in the region in the available material. What does appear is an exportable risk, since the model, a checkout skimmer on an e-commerce platform, can be replicated in other markets with equivalent payment methods.
Brazil
Brazil is the only country with verifiable impact in the material and concentrates the discovery, validation, defensive response and official guidance. Folha de S.Paulo, UOL Tilt, O Tempo, Folha Vitória, Ground News, O Povo, TRBN, Olhar Digital and Procon-SP all agree on the same core facts: 90 compromised stores, mostly small and mid-sized, with Magento prevalent and sectors including optical shops, auto parts, fashion and online fundraising.
The most relevant vector is the silent replacement of the QR Code and Pix Copia e Cola during checkout. O Povo adds an important nuance, saying the legitimate QR code is replaced before it is shown on screen, without changing the page’s appearance. That reinforces the idea that the fraud relies on the user’s visual trust and on the legitimacy of the store URL or branding.
TRBN adds an infrastructure detail that does not appear in the other notes reviewed, six different command-and-control domains used to inject the malicious code. Although the material does not publish those domains, the detail suggests operational redundancy and a campaign with the ability to re-inject or maintain persistence across multiple sites. TRBN also stresses that the target is e-commerce, not the consumer’s device.
On mitigation, the consensus is clear. Merchants should update the platform, change admin passwords, use 2FA and monitor the site with security software. Users should validate the name, CNPJ and amount in the banking app before authorizing payment. If the transaction was diverted, the next step is to contact the bank and start MED, which according to Procon-SP now has a window of up to 80 days.
Technical indicators
No hashes, IPs or concrete domains were published in the notes reviewed. The only technical infrastructure detail identified in the material is TRBN’s mention of six command-and-control domains, without a public list or observable values.
| Type | Value | Source |
|---|---|---|
| C2 | Six command-and-control domains, not publicly identified | TRBN |
| Affected platform | Magento, mentioned as the base used by most infected sites | Folha de S.Paulo |
| Behavior | Replacement of the Pix QR code and Pix Copia e Cola at checkout | Folha de S.Paulo, UOL Tilt, O Tempo |
Analysis for security teams
The immediate priority for an e-commerce team is to assume the problem lives in the checkout frontend, not only in the payment layer. That means reviewing script integrity, templates and extensions, especially on platforms like Magento, which appear repeatedly in the material. If the site uses third-party payment tools or embedded widgets, external dependencies and recent changes in the purchase flow should also be reviewed.
The lack of public IOCs limits signature-based detection. In that environment, practical defense comes down to three pillars. First, change control and integrity monitoring over checkout files. Second, review administrative accounts, with unique passwords and 2FA. Third, alerts for anomalous rendering of the QR code and Pix Copia e Cola, especially if they vary by device or session.
For operational monitoring, it makes sense to correlate checkout changes with spikes in disputes or customer complaints about paying the wrong recipient. There is no need to wait for a formal complaint to review the environment. If a store operates in Brazil and processes Pix, Procon-SP’s note about the MED window being extended to 80 days also suggests keeping a documented internal response process, because potential reimbursement does not replace containment and root-cause analysis.
For end users, the best guidance remains banking app verification. The sources agree that the recipient name and CNPJ must match the store or the payment intermediary. If the payment goes to an unknown individual or a different recipient, the purchase should stop. If the diversion has already happened, the bank must be contacted immediately to log the incident and activate MED.
Frequently asked questions
What do the sources combine about the scope and vector of the fraud?
The sources combine two data points: the scope measured by Kaspersky, which reaches 90 Brazilian stores, and the vector, a malware injected into checkout to replace the Pix QR code and Pix Copia e Cola. That combination makes this an e-commerce campaign, not an isolated incident.
What makes this case different from a common Pix fraud?
The difference is that the user enters a legitimate page and the change happens inside the store site at payment time. There is no crude spoofing of the interface. In addition, TRBN points to six C2 domains and Olhar Digital adds the possible copying of card data.
What signs can help detect it before confirming payment?
The practical signal is to check the recipient name, CNPJ and amount in the banking app before authorizing Pix. If the data do not match the store or its payment intermediary, the transaction should be stopped. That recommendation appears in Folha de S.Paulo, Folha Vitória and Procon-SP.
What should a Brazilian merchant do if compromise is suspected?
It should prioritize platform updates, changing administrative passwords, two-factor authentication and monitoring with security software. O Tempo and Olhar Digital add that on Magento, the checkout and dependencies should be reviewed regularly. The key is to treat it as a site compromise, not a customer problem.
What official option exists if the money already left incorrectly?
The sources recommend contacting the bank or payment institution immediately and requesting the Special Return Mechanism. Procon-SP says Brazil’s central bank extended the MED deadline from 30 to 80 days after the mistaken transfer, which expands the response window.
Is there attribution to a criminal group or a specific country?
No. The notes reviewed speak generically of criminals or scammers and do not attribute the campaign to an identified group or a state. They also do not publish hashes, concrete C2 domains or code samples, except for TRBN’s mention of six command-and-control domains.
Material limitations
The material does not allow identification of the malware authors, code families, hashes, IPs or concrete command-and-control domains. There is also no attribution to a criminal group or a country. The infrastructure cited by TRBN is limited to the number of C2 domains, without actionable indicators.
The journalistic sources reviewed focus on the fraud behavior, the approximate number of affected stores and mitigation guidance. They do not provide forensic evidence, malicious code captures or reverse-engineering analysis. For that reason, the technical reconstruction has to remain at the level of the campaign and observable TTPs from public coverage.
There are also no verifiable data showing impact outside Brazil. Argentina, Chile, Paraguay, Bolivia, Peru, Colombia, Mexico, the United States and Uruguay have no confirmed facts in the available research. The regional reading, for now, is one of model exportability, not confirmed expansion.
Sources
- Golpe do Pix: vírus troca QR Code e Pix Copia e Colawww1.folha.uol.com.br· Folha de S.Paulo
- Novo golpe altera QR Code do Pix em lojas onlineuol.com.br· UOL Tilt
- Novo vírus altera QR Code do Pix em compras online no Brasiltemabr.com· Temabr
- Saiba como se proteger de novo golpe que modifica QR Code e rouba Pix de compras em lojas onlineotempo.com.br· O Tempo
- Atenção! Novo vírus altera QR Code do Pix em compras online no Brasiljaimaginouisso.com.br· Jaimaginou Isso
- New coup changes QR Pix code in virtual stores and diverts moneyground.news· Ground News
- Golpe do Pix invade lojas virtuais e pode desviar dinheiro sem o consumidor perceberfolhavitoria.com.br· Folha Vitória
- Golpe consegue trocar QR Code do Pix sem mudar a aparência da página e já atingiu lojas onlineopovo.com.br· O Povo
- Golpe do Pix sequestra QR Code de lojas verdadeiras sem deixar sinais e mira consumidores na Bahiatrbn.com.br· TRBN
- Confira o Olhar Digital News na íntegra (08/09/2026)olhardigital.com.br· Olhar Digital
- Novo vírus altera QR Code do Pix em compras online no Brasilyoutube.com· Olhar Digital
- Procon orienta consumidores sobre novo golpe em compra on-linesampi.net.br· Procon-SP / Sampi
- Nuevo malware modifica códigos QR de Pix y desvía pagos en ecommercepaymentmedia.com· PaymentMedia



