New Virus Targets Brazilian E-commerce by Manipulating Pix Payments
2 sources · Brazil
Who reported this
- UOL
- Folha de S.Paulo
What the colours mean
- Left
- Centre-left
- Centre
- Centre-right
- Right
- A hatched block means the outlet is affiliated with, or controlled by, a state.
Political lean describes where an outlet sits within the politics of its own country. It is never a position on a single global scale.
Political lean is comparable inside one country and not across them, which is why the bar groups by country first. Publicly funded broadcasters are not marked as state-linked.
The owner of each outlet is listed as a matter of record, not as a judgement about the outlet.
Every source for this story reports from Brazil.
A new type of virus is targeting Brazilian e-commerce sites by imperceptibly altering Pix QR codes and Copy and Paste codes during the payment process. According to security firm Kaspersky and independent researcher eremit4, the malware replaces the original payment code with a fraudulent one, diverting funds directly to the accounts of scammers. The virus specifically targets small and medium sized online stores using the free platform Magento, with Kaspersky detecting 90 infected sites in Brazil.
Fabio Assolini, a director at Kaspersky, stated that the potential for damage is high because the virus infects the website rather than the user's computer. This method leaves no visual trace for the customer. Additionally, the malware can steal credit card data for future cloning if the customer chooses that payment method instead of Pix. In such cases, the merchant still receives the payment, but the customer is defrauded later.
To protect themselves, buyers are advised to verify the recipient's name before confirming a Pix transaction and to use virtual credit cards. Merchants are encouraged to keep Magento updated, use complex administrative passwords, and monitor for anomalous behavior. While the Central Bank recommends the Special Return Mechanism (MED) to track fraudulent transactions, Assolini noted that scammers often distribute stolen funds across dozens of shell accounts within hours to bypass the system's five transfer tracking limit.
Both reports provided identical technical details and warnings, presenting the event as a cybersecurity threat without differing political framing.
How each side framed it
- Centre-left
- The report focused on the technical aspects of the fraud and provided practical security advice for consumers and merchants.
- Centre
- The report focused on the technical aspects of the fraud and provided practical security advice for consumers and merchants.
Sources
100% of the statements in this article were traced back to the source articles listed above.