CiberLATAMbywhalemate

Brazil malware swaps Pix QR codes in e-commerce

Kaspersky found 90 Brazilian stores infected with malware that replaces Pix QR codes and Pix Copia e Cola at checkout.

Whalemate Labs · AI-assisted researchPublished:38 min read

Kaspersky validated a finding attributed to independent researcher eremit4 about a campaign that quietly alters Pix QR Codes and the Pix Copia e Cola field on checkout pages at Brazilian e-commerce sites. The reported scope reaches 90 small and mid-sized stores, mostly built on Magento, with affected sectors including optical shops, auto parts, fashion and online fundraising sites. The core mechanism is checkout hijacking: shoppers see the legitimate page, but when they choose Pix, the code shown has already been replaced with one controlled by criminals, so the money ends up in accounts not linked to the store. Several reports also say the same malicious code can extend its reach to credit card data processed at checkout, bringing the case closer to classic skimming on the e-commerce site itself.

The case, in the notes reviewed, was not attributed to a named criminal group or a country of origin, and no hashes, domains or code samples were provided. TRBN did add one relevant technical detail, saying the campaign used six command-and-control domains to inject the malicious code into compromised sites. The coverage also stresses that the target is the e-commerce infrastructure, not customer devices, which multiplies the impact because it affects every shopper on an infected store without needing endpoint compromise.

On defense, the material converges on practical steps for merchants and consumers. For stores, Kaspersky advises keeping the platform updated, changing admin passwords, strengthening two-factor authentication and monitoring the site with security software. For users, the guidance is to avoid confirming Pix automatically after scanning a QR code, verify the recipient name, CNPJ and amount in the banking app, and distrust transfers to unknown individuals. If the transfer has already gone to the wrong recipient, the sources recommend contacting the bank or payment institution immediately, filing the incident and requesting the Special Return Mechanism, whose usage window was recently extended from 30 to 80 days by Brazil’s central bank, according to Procon-SP.

Executive summary

Kaspersky validated, based on a finding from an independent researcher identified as eremit4, a malware campaign that quietly alters Pix QR Codes and the Pix Copia e Cola field on checkout pages at Brazilian e-commerce sites. Public reporting puts the reach at 90 small and mid-sized stores, mostly built on Magento, with affected sectors including optical shops, auto parts, fashion and online fundraising sites.

The behavior described by the sources is consistent. A user reaches a legitimate payment page, selects Pix and, at that point, the code on screen has already been replaced by one controlled by criminals. The transaction ends up in accounts unrelated to the store, with no visible change in the interface, which makes real-time detection difficult. Several reports add that the same malicious code can also copy credit card data processed at checkout, expanding the case beyond Pix fraud into a skimming scenario on the merchant page itself.

According to the notes reviewed, the operation was not attributed to a named criminal group or a specific country. The operators are referred to generically as criminals or scammers. No technical IOCs were published in the journalistic pieces analyzed, except for one point from TRBN, which says the campaign uses six different command-and-control domains to inject the malicious code into compromised sites. That is enough to describe a web injection campaign rather than an endpoint fraud scheme.

From a defensive standpoint, the material converges on three lines. For merchants, keep the platform updated, change admin passwords, strengthen 2FA and monitor the site with security software. For consumers, verify the recipient name, CNPJ and amount in the banking app before authorizing Pix, and do not confirm the transaction automatically after scanning the QR code. If the diversion already happened, the sources recommend contacting the bank or payment institution immediately, filing the incident and activating the [Special Return Mechanism](https://sampi.net.br/jundiai/noticias/3004100/jundiai/2026/09/procon-orienta-consumidores-sobre-novo-golpe-em-compra-online), whose window was extended from 30 to 80 days by Brazil’s central bank, according to Procon-SP.

Context and background

The campaign appears at a time when Pix has already become a mass payment rail in Brazil and, for that reason, an attractive surface for checkout fraud. The novelty is not social engineering or obvious interface spoofing, but where the code is inserted. It is injected into the e-commerce site itself and triggered exactly when the user chooses to pay. The result is an almost invisible replacement of the QR Code and the copy-and-paste text.

According to Folha de S.Paulo, the public discovery happened on September 1, 2026 and was carried out by the independent researcher eremit4. The same coverage says the researcher described the threat as the new Brazilian magecart, a useful comparison because it places the case in the family of attacks that operate on legitimate payment pages to intercept value or sensitive data.

Kaspersky’s later validation turned an individual observation into a campaign with measurable reach. The figure of 90 infected stores is repeated by Folha de S.Paulo, UOL Tilt, Folha Vitória, Ground News and other reports, which suggests a solid journalistic consensus on the scale. Most affected sites would be small and mid-sized merchants, many on Magento, a detail that helps explain the homogeneity of the compromised surface.

At the same time, the reporting makes clear that the effect is not limited to Pix. Olhar Digital and the case video add that the same code can copy credit card data processed at checkout. That broader function points to malware designed around the purchase session, not only one payment method.

2026-09-01 eremit4discoversthemalware 2026-09-07 Folha warnsabout a tamperedPix QR code 2026-09-07 Kasperskyconfirms 90stores 2026-09-08 O Tempo explainsthe detour 2026-09-11 TRBN cites sixdifferent C2s 2026-09-11 Procon-SPextendsMED to 80days
Pix malware timeline — From eremit4's discovery to Procon-SP's guide and the detail of six C2 domains.

Key facts table

Date Event Source Confidence
2026-09-01 Independent researcher eremit4 discovers the malware that alters Pix in Brazilian e-commerce sites. Folha de S.Paulo confirmed
2026-09-07 Folha de S.Paulo reports that Kaspersky warned about a virus that swaps the Pix QR code for a fraudulent one at checkout. Folha de S.Paulo confirmed
2026-09-07 Folha de S.Paulo says Kaspersky validated the finding and detected 90 infected sites, mostly or all on Magento. Folha de S.Paulo confirmed
2026-09-08 O Tempo explains that the malware invades the payment page and alters the QR and Pix Copia e Cola to divert funds. O Tempo confirmed
2026-09-08 O Tempo publishes Kaspersky’s recommendations for merchants, including updates, passwords and 2FA. O Tempo confirmed
2026-09-08 Folha de S.Paulo recommends checking the recipient name, CNPJ and amount in the banking app before confirming Pix. Folha de S.Paulo confirmed
2026-09-09 UOL Tilt reports 90 affected e-commerce sites, mainly in optical goods, auto parts, fashion and online fundraising. UOL Tilt confirmed
2026-09-09 Olhar Digital adds that the malicious code can also copy credit card data. Olhar Digital confirmed
2026-09-11 TRBN says the campaign uses six command-and-control domains to inject the code. TRBN confirmed
2026-09-11 Procon-SP offers guidance on verifying data and using MED 2.0 after mistaken transfers. Procon-SP / Sampi confirmed
2026-09-11 Procon-SP says the MED deadline was extended from 30 to 80 days. Procon-SP / Sampi confirmed

Operation timeline

Date Event Actor/vector Verified source
2026-09-01 Initial detection of the malware in Brazilian stores. eremit4, checkout analysis Folha de S.Paulo
2026-09-07 First report on discreet replacement of the Pix QR code. Folha de S.Paulo, Kaspersky Folha de S.Paulo
2026-09-07 Kaspersky validates the finding and estimates 90 compromised sites. Kaspersky, e-commerce with Magento Folha de S.Paulo
2026-09-08 Guidance is circulated for consumers and merchants. O Tempo, Kaspersky O Tempo
2026-09-09 New sector details and the extension to credit cards emerge. UOL Tilt, Olhar Digital UOL Tilt, Olhar Digital
2026-09-11 The six C2 domains detail is added. TRBN, injection infrastructure TRBN
2026-09-11 Procon-SP publishes response guidance and MED 2.0. Procon-SP, consumer, bank Procon-SP / Sampi
Legitimate site Magento checkout Web injection Obfuscated script QR and copy-paste Invisible replacement Criminal account Payment diversion Customer chooses Pix The code alters the view No visible signal Money goes out of the store
Checkout attack flow — The injection lives on the merchant site and swaps the payment details before they appear.

Attack chain and TTPs

The chain described by the sources is an intrusion on the e-commerce site itself. In principle, this is not a compromise of the buyer’s device, but of the merchant’s payment page. When the customer selects Pix, the malicious script intervenes in the rendering of the QR Code and the Pix Copia e Cola field, replacing legitimate information with data controlled by the attacker.

That changes the detection problem. From the user’s perspective, the experience looks normal because the interface shows no visible changes. From the merchant’s perspective, the issue sits in the code loaded into the checkout, which in many cases is obfuscated, according to Folha de S.Paulo’s reference to a Kaspersky director. The report says the replacement is triggered by a strange piece of code, often written in obfuscated lines, which reinforces the hypothesis of frontend tampering or injection in the checkout script chain.

The same flow explains why a single compromised site can have broad impact. If a store receives many daily visits, each buyer is exposed at the exact moment of payment. TRBN sums it up well by saying the malware targets the e-commerce structure, not customer machines. The operational focus is the merchant’s server or web environment, not the user endpoint.

The sources also suggest a broader functional scope. Olhar Digital says the same code can copy credit card data processed at checkout. That fits a multipurpose skimming logic, where the attacker seeks value in different forms within the same payment page. The Magecart comparison made by eremit4 makes sense in that context, because it connects payment fraud and data capture.

TTP Description Source
Checkout injection The malicious code is inserted into the legitimate ecommerce payment page. Folha de S.Paulo, TRBN
Pix QR manipulation The QR Code shown to the user is replaced with one controlled by criminals. UOL Tilt, O Tempo, O Povo
Pix Copia e Cola tampering The copy-and-paste field or text is also modified before display. Folha de S.Paulo, UOL Tilt, Folha Vitória
Obfuscation Kaspersky describes a strange piece of code, often obfuscated. Folha de S.Paulo
C2 infrastructure TRBN reports six command-and-control domains. TRBN
Card skimming The same code can copy credit card data processed at checkout. Olhar Digital, YouTube
TTP Description Effect Source Status Injection Checkout code Compromises payment Folha, TRBN Confirmed Tampering QR and copy-paste Pix diversion UOL, O Tempo Confirmed Obfuscation Suspicious script Hard to spot Folha Confirmed Multiple C2 Six domains Operational persistence TRBN Confirmed
Malware TTP Matrix — Techniques observed in the campaign according to press coverage.

Regional impact

Regional overview

The case has broad regional coverage in Brazilian media, but the verifiable impact in the sources is concentrated in Brazil. The campaign affects small and mid-sized stores, with a compromise pattern that hits the checkout experience and, by extension, anyone paying with Pix from those sites.

The most solid regional reading is operational, not geopolitical. There is no state attribution or public evidence of spread to other countries in the region in the available material. What does appear is an exportable risk, since the model, a checkout skimmer on an e-commerce platform, can be replicated in other markets with equivalent payment methods.

Brazil

Brazil is the only country with verifiable impact in the material and concentrates the discovery, validation, defensive response and official guidance. Folha de S.Paulo, UOL Tilt, O Tempo, Folha Vitória, Ground News, O Povo, TRBN, Olhar Digital and Procon-SP all agree on the same core facts: 90 compromised stores, mostly small and mid-sized, with Magento prevalent and sectors including optical shops, auto parts, fashion and online fundraising.

The most relevant vector is the silent replacement of the QR Code and Pix Copia e Cola during checkout. O Povo adds an important nuance, saying the legitimate QR code is replaced before it is shown on screen, without changing the page’s appearance. That reinforces the idea that the fraud relies on the user’s visual trust and on the legitimacy of the store URL or branding.

TRBN adds an infrastructure detail that does not appear in the other notes reviewed, six different command-and-control domains used to inject the malicious code. Although the material does not publish those domains, the detail suggests operational redundancy and a campaign with the ability to re-inject or maintain persistence across multiple sites. TRBN also stresses that the target is e-commerce, not the consumer’s device.

On mitigation, the consensus is clear. Merchants should update the platform, change admin passwords, use 2FA and monitor the site with security software. Users should validate the name, CNPJ and amount in the banking app before authorizing payment. If the transaction was diverted, the next step is to contact the bank and start MED, which according to Procon-SP now has a window of up to 80 days.

Verifiable coverage by country Brazil, confirmed facts 90 stores, Pix, and Magento Argentina, Chile, Paraguay, Bolivia, Peru, Colombia, Mexico, the United States, and Uruguay No additional verifiable facts in the research AR CL PY BO PE CO MX US UY
Regional impact map — Verifiable evidence is concentrated in Brazil; the rest of the region has no confirmed facts in the research.

Technical indicators

No hashes, IPs or concrete domains were published in the notes reviewed. The only technical infrastructure detail identified in the material is TRBN’s mention of six command-and-control domains, without a public list or observable values.

Type Value Source
C2 Six command-and-control domains, not publicly identified TRBN
Affected platform Magento, mentioned as the base used by most infected sites Folha de S.Paulo
Behavior Replacement of the Pix QR code and Pix Copia e Cola at checkout Folha de S.Paulo, UOL Tilt, O Tempo

Analysis for security teams

The immediate priority for an e-commerce team is to assume the problem lives in the checkout frontend, not only in the payment layer. That means reviewing script integrity, templates and extensions, especially on platforms like Magento, which appear repeatedly in the material. If the site uses third-party payment tools or embedded widgets, external dependencies and recent changes in the purchase flow should also be reviewed.

The lack of public IOCs limits signature-based detection. In that environment, practical defense comes down to three pillars. First, change control and integrity monitoring over checkout files. Second, review administrative accounts, with unique passwords and 2FA. Third, alerts for anomalous rendering of the QR code and Pix Copia e Cola, especially if they vary by device or session.

For operational monitoring, it makes sense to correlate checkout changes with spikes in disputes or customer complaints about paying the wrong recipient. There is no need to wait for a formal complaint to review the environment. If a store operates in Brazil and processes Pix, Procon-SP’s note about the MED window being extended to 80 days also suggests keeping a documented internal response process, because potential reimbursement does not replace containment and root-cause analysis.

For end users, the best guidance remains banking app verification. The sources agree that the recipient name and CNPJ must match the store or the payment intermediary. If the payment goes to an unknown individual or a different recipient, the purchase should stop. If the diversion has already happened, the bank must be contacted immediately to log the incident and activate MED.

Frequently asked questions

What do the sources combine about the scope and vector of the fraud?

The sources combine two data points: the scope measured by Kaspersky, which reaches 90 Brazilian stores, and the vector, a malware injected into checkout to replace the Pix QR code and Pix Copia e Cola. That combination makes this an e-commerce campaign, not an isolated incident.

What makes this case different from a common Pix fraud?

The difference is that the user enters a legitimate page and the change happens inside the store site at payment time. There is no crude spoofing of the interface. In addition, TRBN points to six C2 domains and Olhar Digital adds the possible copying of card data.

What signs can help detect it before confirming payment?

The practical signal is to check the recipient name, CNPJ and amount in the banking app before authorizing Pix. If the data do not match the store or its payment intermediary, the transaction should be stopped. That recommendation appears in Folha de S.Paulo, Folha Vitória and Procon-SP.

What should a Brazilian merchant do if compromise is suspected?

It should prioritize platform updates, changing administrative passwords, two-factor authentication and monitoring with security software. O Tempo and Olhar Digital add that on Magento, the checkout and dependencies should be reviewed regularly. The key is to treat it as a site compromise, not a customer problem.

What official option exists if the money already left incorrectly?

The sources recommend contacting the bank or payment institution immediately and requesting the Special Return Mechanism. Procon-SP says Brazil’s central bank extended the MED deadline from 30 to 80 days after the mistaken transfer, which expands the response window.

Is there attribution to a criminal group or a specific country?

No. The notes reviewed speak generically of criminals or scammers and do not attribute the campaign to an identified group or a state. They also do not publish hashes, concrete C2 domains or code samples, except for TRBN’s mention of six command-and-control domains.

Material limitations

The material does not allow identification of the malware authors, code families, hashes, IPs or concrete command-and-control domains. There is also no attribution to a criminal group or a country. The infrastructure cited by TRBN is limited to the number of C2 domains, without actionable indicators.

The journalistic sources reviewed focus on the fraud behavior, the approximate number of affected stores and mitigation guidance. They do not provide forensic evidence, malicious code captures or reverse-engineering analysis. For that reason, the technical reconstruction has to remain at the level of the campaign and observable TTPs from public coverage.

There are also no verifiable data showing impact outside Brazil. Argentina, Chile, Paraguay, Bolivia, Peru, Colombia, Mexico, the United States and Uruguay have no confirmed facts in the available research. The regional reading, for now, is one of model exportability, not confirmed expansion.

Sources

View all