VMTech
Discuss a project

Slim Spider Targets Crypto Custody Secrets at Brazilian Financial Firm

Slim Spider Targets Crypto Custody Secrets at Brazilian Financial Firm

Cloud intrusion focused on custody credentials and Pix access

CrowdStrike has identified a previously undocumented, financially motivated threat actor called Slim Spider, which has targeted Brazilian financial institutions since at least March 2026. The Brazil-based group was observed conducting a multi-stage intrusion against a financial institution in late March, targeting cryptocurrency assets and accounts connected to Brazil’s Pix instant-payment system.

The incident centred on cloud access. CrowdStrike said Slim Spider created custom Bash scripts that queried cloud instance metadata over socket connections to obtain temporary cloud credentials. After gaining a foothold in the victim’s cloud environment, the attackers enumerated secrets held in the cloud credential manager and used the sed command to clone and alter scripts used to extract them.

The activity was directed at credentials associated with digital financial assets. After exfiltrating digital-asset custody secrets, the group invoked cast, a component of the Foundry Ethereum development toolkit, to derive the Ethereum wallet address associated with a stolen private key.

Native tooling and DevOps access extended the attack

Rather than introducing third-party cryptographic libraries, Slim Spider performed cloud-native cryptographic signing with OpenSSL from within its Bash scripts. CrowdStrike described that choice as an effort to reduce detection risk while operating inside cloud environments.

The attackers also sought access to nodes in a cloud container service cluster. They deployed backdoors made to resemble infrastructure-related binaries, a technique intended to make malicious tooling blend with legitimate operational components.

From there, Slim Spider pivoted to Azure DevOps, likely with compromised credentials, and ran malicious pipelines that distributed further implants across a managed Kubernetes cluster. One implant was named spi, apparently impersonating the Sistema de Pagamentos Instantâneos, the central infrastructure used to process Pix payments in Brazil.

Panels support reconnaissance and fraudulent transfers

CrowdStrike linked the group to several web panels that automate parts of the intrusion chain. NEXUS // Scanner categorises API endpoints into 16 groups, including fintech, banking, payment and cryptocurrency, and ranks them by availability and authentication options using Ollama. A separate Painel de Emails Entra ID searches compromised Microsoft 365 mailboxes using finance, admin and Brazil categories.

Another tool, Painel Pix, was designed to initiate bulk unauthorised Pix transfers from compromised accounts. CrowdStrike also found an exposed command-and-control panel connected to the actor that showed compromised hosts at several Brazilian banks and fintech organisations and likely exfiltrated archive files. The group’s arsenal includes MikeDor, a Go-based backdoor capable of collecting sensitive information and monitoring user activity.

Business implication

For financial organisations, the case makes cloud credentials, secret stores, CI/CD platforms and Kubernetes administration paths part of the control boundary for payment systems and cryptocurrency custody. Defences need to account for how a compromise of those operational services can expose the credentials nearest to high-value financial assets.

#cloudsecurity#cryptosecurity#devopssecurity#paymentsecurity
Open analytics
On the site 0 views
min read 4 08.09.2026
Instagram

Slim Spider Targets Crypto Custody Secrets at Brazilian Financial Firm

Open the post on Instagram ↗