LLM-Assisted Financial Cybercrime Wave Hits Latin American Banks and Government Targets
CrowdStrike, Google/Mandiant, Unit 42 and Trend Micro detail overlapping financially motivated campaigns against Brazilian financial institutions — including the new 'Slim Spider' group's theft of crypto-custody secrets and Unit 42's finding that clusters…
Multiple vendors have disclosed a wave of financially motivated intrusions across Latin America. CrowdStrike is tracking 'Slim Spider,' a previously undocumented group attacking Brazilian financial institutions since at least March 2026: it used custom Bash scripts to steal temporary cloud credentials from cloud credential managers, exfiltrated digital asset custody secrets, used Foundry's cast tool to derive Ethereum wallet addresses, deployed a Go-based backdoor called MikeDor and an implant impersonating Brazil's SPI instant payment infrastructure, and pivoted into Azure DevOps and Kubernetes clusters. Slim Spider also used web panels — NEXUS // Scanner, Painel de Emails Entra ID, and Painel Pix — for reconnaissance and unauthorized Pix transfers. Separately, Google Threat Intelligence Group and Mandiant disclosed 'Breeze Comet' (CL-CRI-1163), a Portuguese-speaking group active since 2024 that breaches Brazilian payment infrastructure to run fraudulent Pix, Boleto, and STR transactions. Unit 42 then linked CL-CRI-1163 to a second cluster, CL-CRI-1131, via shared SOCKS5 relay infrastructure. CL-CRI-1131 compromised a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador using native Windows tools, numbered batch scripts, and Volume Shadow Copies to dump the SAM registry hive and NTDS.dit. CL-CRI-1163 targeted Brazilian financial organizations with phishing (described as job-themed by one report and resume-themed by another), custom RATs, and SockTz, a Go-based reverse SOCKS5 tunneling utility deployed in nine versions within roughly two hours. An exposed self-hosted NextChat interface on attacker infrastructure showed operators used commercial LLMs Claude and GPT-4.1 to generate and debug post-exploitation scripts; Unit 42 assessed AI reduced intrusion troubleshooting time after initial access rather than replacing the attacker. Trend Micro tracks related AI-augmented activity as SHADOW-AETHER-040 and SHADOW-AETHER-064.
- CrowdStrike attributes attacks on Brazilian financial institutions since at least March 2026 to previously undocumented group 'Slim Spider,' which stole temporary cloud credentials via custom Bash scripts and exfiltrated digital asset…
- Slim Spider tooling includes the Go-based MikeDor backdoor, an implant impersonating Brazil's SPI instant payment infrastructure, and Foundry's cast tool to derive Ethereum wallet addresses; the actor also pivoted to Azure DevOps and…
- Slim Spider used panels named NEXUS // Scanner, Painel de Emails Entra ID, and Painel Pix for reconnaissance and unauthorized Pix transfers.
- Google Threat Intelligence Group and Mandiant separately track CL-CRI-1163 as 'Breeze Comet,' a Portuguese-speaking group since 2024 running fraudulent Pix, Boleto, and STR transactions against Brazilian payment infrastructure.
- Unit 42 ties clusters CL-CRI-1131 and CL-CRI-1163 together via shared SOCKS5 relay infrastructure and use of LLMs during operations.
- CL-CRI-1131 victims include a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador; the cluster used living-off-the-land techniques and Volume Shadow Copies to dump SAM registry hives and…
- CL-CRI-1163 targeted Brazilian financial organizations with phishing, custom RATs, and SockTz, a Go-based reverse SOCKS5 tunneling utility, with versions 1-9 deployed within roughly two hours.
- An exposed self-hosted NextChat interface revealed operators used Claude and GPT-4.1 to generate workaround scripts and troubleshoot execution failures; Unit 42 judged AI shortened post-access troubleshooting rather than replacing the…
Coverage timelineoldest first · each row is one article
- · 7d agoSlim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
The Hacker News· 75
CrowdStrike links previously unseen Slim Spider group to crypto custody secret theft at Brazilian financial institutions since March 2026.