VMTech
Discuss a project

Breeze Comet targets Brazilian payment infrastructure

Breeze Comet targets Brazilian payment infrastructure

Fraud campaign reaches core payment environments

Breeze Comet, a financially motivated threat actor formerly tracked as UNC5669, has targeted Brazilian financial services, retail and e-commerce organizations since 2024. Google Threat Intelligence Group and Mandiant say the group specializes in manipulating payment systems and banking software to conduct fraudulent transfers.

The group has executed hundreds of fraudulent transactions after reaching core financial applications. Google reported at least one heist involving assets worth tens of thousands of US dollars. CrowdStrike tracks overlapping activity as Plump Spider, while Trend Micro uses the name SHADOW-AETHER-064.

The principal targets are organizations permitted to process transactions through banking software, APIs and systems including Pix, STR and Boleto. This includes banks, payment processors, retailers, exchanges, fintech companies and banking software providers.

Multiple routes to privileged financial access

Breeze Comet has used password spraying and voice calls impersonating IT support to persuade victims to install remote monitoring and management tools such as AnyDesk. In an incident highlighted by Axur in November 2025, operators posing as support staff on WhatsApp guided a victim to run a PowerShell reconnaissance script presented as a corporate application update.

The group has also exploited vulnerable JBoss AS servers to deploy web shells and deliver Chisel and other proxy utilities. Compromised Brazilian small-government websites have staged RMM tools, tax- or receipt-themed infostealers and XWorm, while also serving as command-and-control endpoints that can evade reputation filtering.

To complete a payment operation, the actor needs access to the National Financial System Network through an authorized entity, mTLS credentials for authenticated Pix or STR transaction payloads, multiple accounts in Active Directory and cloud environments, and knowledge of transfer procedures, controls, integrations and anti-fraud systems.

Tunnelling, persistence and evidence removal

For internal discovery and privilege escalation, the operators have used Impacket, ADRecon, ADVipscan and their REALBREEZE LDAP brute-forcing utility. They move laterally through unauthorized RDP sessions and SMB shares, and have connected rogue hardware directly to retail networks to establish footholds.

COBALTSPIN, a Rust-based routing malware, creates a reverse SOCKS5 proxy over WebSocket connections. Google says this allows traffic to move between command-and-control infrastructure and internal targets through boundary firewalls without relying on built-in persistence mechanisms that could draw attention.

Persistence has progressed from commercial RMM tools in 2024 to malicious Kubernetes pods in 2025 and the exfiltration of cloud secrets to public notepad sites. The malware set also includes LIGHTPAINT, MILDFROST, KICKPLATE and BOATBEAM. Operators have disabled Windows Defender real-time monitoring with PowerShell, then cleared event logs and deleted directories after fraudulent transfers.

Google also noted verbose comments and standardized execution headers that indicate possible large language model use in malware development. For businesses connected to financial APIs, the practical priority is to protect mTLS credentials, verify every support-driven remote-access request, and monitor privileged access and transaction activity for unexpected paths.

#cybersecurity#financialfraud#paymentsecurity#threatintel
Open analytics
On the site 0 views
min read 4 01.09.2026
Instagram

Breeze Comet targets Brazilian payment infrastructure

Open the post on Instagram ↗