Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Google Threat Intelligence details BREEZE COMET, a financially motivated group manipulating Brazilian payment systems and banking software to conduct fraudulent transfers since 2024.
Mandiant and Google Threat Intelligence Group (GTIG) track this activity as BREEZE COMET (formerly UNC5669), active since 2024 against Brazilian financial services, retail, and eCommerce organizations. The actor specializes in manipulating payment systems and banking software to conduct fraudulent transfers. The activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. The report details the group's tactics, toolkit, mitigations, and detections for this active and developing threat.
55