BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
CIPHERThreat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
β€’
Β© 2026
β€’
blacktemple.net
  1. Feed
  2. /Weekly Threat Roundup: New Banking Trojan, Security Tools, and AI Platform Updates

Weekly Threat Roundup: New Banking Trojan, Security Tools, and AI Platform Updates

March 16, 2026Malware & Threats2 min readmedium

Originally reported by BleepingComputer, Malwarebytes Labs, SecureList (Kaspersky)

#banking-trojan#gopix#memory-malware#secrets-scanner#betterleaks#chatgpt#weekly-roundup
Share

TL;DR

Kaspersky researchers identified GoPix, a sophisticated Brazilian banking trojan that operates entirely in memory and uses advanced techniques like PAC file manipulation for man-in-the-middle attacks. Meanwhile, security teams gained a new open-source secrets scanning tool called Betterleaks.

Why medium?

The GoPix banking trojan represents a sophisticated threat targeting financial institutions with advanced techniques, warranting medium severity. Other stories are informational security tool releases and platform updates.

GoPix Banking Trojan Leverages Memory-Only Techniques

Kaspersky's Global Research and Analysis Team (GReAT) has documented a sophisticated Brazilian banking trojan dubbed GoPix that employs several advanced evasion techniques. According to the research, GoPix operates entirely within system memory without writing files to disk, significantly complicating detection efforts.

The malware utilizes Proxy AutoConfig (PAC) files to conduct man-in-the-middle attacks against banking websites, allowing threat actors to intercept and manipulate user communications with financial institutions. Additionally, GoPix spreads through malvertising campaigns distributed via Google Ads, demonstrating the threat actors' ability to leverage legitimate advertising platforms for initial access.

Kaspersky researchers describe the trojan as "unprecedentedly complex" within the Brazilian banking malware ecosystem, indicating a significant evolution in threat actor capabilities targeting South American financial institutions.

Betterleaks Emerges as Gitleaks Alternative

Security practitioners have gained access to a new open-source secrets detection tool called Betterleaks, positioned as an alternative to the established Gitleaks scanner. The tool can analyze directories, files, and git repositories to identify exposed secrets using both default detection rules and custom configurations.

Betterleaks joins the growing ecosystem of automated secrets detection tools designed to prevent credential exposure in code repositories and file systems. The availability of multiple open-source options provides security teams with additional flexibility in implementing secrets scanning across development workflows.

OpenAI Clarifies ChatGPT Advertising Rollout

OpenAI has confirmed to BleepingComputer that ChatGPT advertisements for Free and Go plan users remain limited to the United States, despite references to advertising appearing in updated privacy policies that concerned international users.

The clarification addresses confusion that arose when users outside the US noticed ad-related language in policy documentation, leading to speculation about broader advertising deployment across OpenAI's global user base.

Weekly Security Digest from Malwarebytes

Malwarebytes Labs published their weekly security roundup covering threat intelligence and security developments from March 9-15, 2026. The digest provides security practitioners with curated threat landscape updates and analysis from the research team.

Sources

  • https://securelist.com/gopix-banking-trojan/119173/
  • https://www.bleepingcomputer.com/news/security/betterleaks-a-new-open-source-secrets-scanner-to-replace-gitleaks/
  • https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-chatgpt-ads-are-not-rolling-out-globally-for-now/
  • https://www.malwarebytes.com/blog/bugs/2026/03/a-week-in-security-march-9-march-15

Originally reported by BleepingComputer, Malwarebytes Labs, SecureList (Kaspersky)

Tags

#banking-trojan#gopix#memory-malware#secrets-scanner#betterleaks#chatgpt#weekly-roundup

Tracked Companies

πŸ‡ΊπŸ‡ΈGoogle

Related Intelligence

  • FBI Seeks Victims of Steam Malware Distribution Campaign

    mediumMar 16, 2026
  • Malware Roundup: 651 Cybercriminals Arrested, New Android Banking Trojan, Critical CCTV Flaw

    criticalFeb 19, 2026
  • AppsFlyer Web SDK Compromised in Supply Chain Attack Targeting Cryptocurrency

    highMar 15, 2026

Related Knowledge

  • CIPHER Deep Training: Malware Analysis, Reverse Engineering, and Evasion Techniques

    offensive
  • Malware Analysis Deep Dive β€” CIPHER Training Module

    dfir
  • DFIR & Threat Hunting Deep Training β€” CIPHER Knowledge Base

    dfir

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← XWorm 7.1 and Remcos RAT Campaigns Exploit WinRAR Vulnerability for Evasion

Next Article

Treasury Report Targets Digital Cash, Tornado Cash Retrial Proceeds β†’