New virus alters Pix QR Code in online purchases in Brazil, diverting consumer funds
Read more
Olhar Digital
olhardigital.com.br

New virus alters Pix QR Code in online purchases in Brazil, diverting consumer funds

A new type of malware compromised 90 virtual stores in Brazil, altering Pix codes in real time during online purchase transactions. The cybersecurity company Kaspersky confirmed the occurrence of the fraud after identification by the independent researcher known as “eremit4”.

According to Folha, this malicious code modifies both the QR Code and the Copy and Paste Pix functionality at the exact moment the end consumer finalizes the purchase. The amounts are then redirected to accounts controlled by scammers, without the buyer noticing any visual indication of irregularity.

The attack specifically targets e-commerce websites that use the Magento platform. When the customer generates the payment to complete their order, a script replaces the original QR Code with a fraudulent code managed by the criminals. Since this modification occurs internally on the website itself, the buyer does not detect any anomaly.

The nature of the attack

The researcher eremit4 nicknamed this operation “the new Brazilian magecart,” alluding to the traditional fraud method used to steal credit card information. Furthermore, if the customer opts for payment via credit card, the same malware has the ability to capture the data for subsequent fraud. In this scenario, the merchant receives the payment normally, but the customer is vulnerable to their card being cloned.

Since the attacker infects the website and not the victim's device, the potential damage is significantly greater, affecting all store customers. Fabio Assolini, director of the Kaspersky investigation team in Latin America, commented on the situation for Folha.

Security and recovery measures

It is crucial for the consumer to identify the fraud quickly to have a chance of recovering the money. The Special Return Mechanism (MED) of Pix allows tracking the transaction for a maximum of five transfers, according to Assolini. However, criminals can disperse the amount across several shell accounts within a few hours, which complicates the recovery of funds.

Assolini stressed that “Criminals know that the limit of traceable transfers is five passes. The MED is valid when the person notices quickly.” Although the consumer has up to 80 days to request the MED, the Central Bank advises that the dispute should be registered even if recovery is not guaranteed, as this helps financial institutions map the accounts used in fraudulent schemes.

Since the payment alteration shows no visible signs, the consumer's main line of defense lies in meticulously verifying the data before authorizing the transfer. Merchants affected by the virus noted an increase in order cancellations. Some opted to disclose the CNPJ and company name so the customer could confirm the Pix beneficiary, while others implemented the use of external payment platforms.

Prevention recommendations

To reduce the risk of future infections, Kaspersky suggests keeping the Magento platform always updated, using strong and unique passwords for administrative access to the site, and performing continuous monitoring with quality software. The code responsible for the attack may be disguised in obfuscated sections, making the detection of malicious behavior difficult. This same threat can also steal card data when the customer chooses this payment method.

If someone identifies a fraudulent Pix, they must access the Pix section in the banking application, select the “Dispute Pix” option, and declare that it is a scam or fraud. The involved accounts may remain blocked for up to 11 days during the investigation process, and any refund will depend on the availability of funds and the analysis of the financial institutions.

Popular