Marthio Marthio
TechnologyBusiness

90 small to mid-size Brazilian e-commerce sites infected by Pix QR code malware since June 2025

Independent security researcher eremit4 discovered a new fraud targeting the PIX payment system. Cybercriminals use six command and control domains to replace official QR codes with malicious ones, stealing transaction values before buyers notice.

Cybersecurity firm Kaspersky reports that 90 small and mid-size Brazilian online retailers are currently infected by malware designed to steal payments via the PIX instant transfer system. The malicious program was identified by independent security researcher eremit4 recently. According to Kaspersky, this attack has been active since June 2025. All known victims operate websites using the open-source e-commerce platform Magento. Criminals utilize six command and control domains to inject harmful code into checkout pages. When customers select PIX for payment, the system instantly swaps the legitimate QR code generated by the store with a fraudulent one, as well as altering the copy and paste data field. The attack operates silently. Store owners often see orders marked as abandoned or pending because official records do not show received funds. Buyers usually become aware of the theft days later when they contact the merchant regarding delivery delays. This time gap allows thieves to distribute the stolen money across different accounts before detection.

Pix paymentQr code scannerBrazilian e CommerceMagento platformCybersecurity breachOnline fraudKasperskyEremit4Command and control domains