ZeroHour
Story · 1 source · 1 articlefirst updated ()1

LLM-Assisted Intrusions and Payment Fraud Hit Latin America: Breeze Comet, Slim Spider, and Unit 42's CL-CRI Clusters

highThreat actorexploited in the wildimportance 82
What's new: First merged summary for this story. New disclosures include: (1) Google/Mandiant publicly naming and profiling Breeze Comet (formerly UNC5669) and its custom malware suite for fraudulent Pix, STR, and Boleto transactions; (2) CrowdStrike documenting Slim Spider for the first time, including the MikeDor backdoor and an SPI-impersonating implant, with activity dated to at least March 2026; (3)…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Google Threat Intelligence Group and Mandiant profiled Breeze Comet, a Brazil-based e-crime group executing hundreds of fraudulent Pix, STR, and Boleto transactions, while CrowdStrike linked the previously undocumented Slim Spider group to crypto custody…

Multiple vendors this week disclosed financially motivated activity targeting Latin America, with a shared focus on Brazil's payment infrastructure. Google Threat Intelligence Group and Mandiant (via The Hacker News, 2026-09-08) profiled Breeze Comet (formerly UNC5669), a financially motivated, Portuguese-speaking group targeting Brazilian financial services, retail, and e-commerce. The group gains access via password spraying, vishing calls impersonating IT support that install RMM tools such as AnyDesk, WhatsApp social engineering, and exploitation of vulnerable JBoss AS servers for web shell deployment. It uses compromised government websites as C2, deploys the Rust-based COBALTSPIN tunneler plus custom backdoors LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, then clears logs after running hundreds of fraudulent transactions through Pix, STR, and Boleto rails that require mTLS credentials and AD/cloud access; at least one heist yielded tens of thousands of dollars, and infrastructure suggests expansion toward Latin America and Africa. Per The Hacker News, Breeze Comet aligns with Unit 42's CL-CRI-1163, CrowdStrike's Plump Spider, and Trend Micro's SHADOW-AETHER-064, though the two THN reports differ on its start date (September 2023 vs. 2024). In a separate disclosure the same day, CrowdStrike introduced Slim Spider, a previously undocumented financially motivated group attacking Brazilian financial institutions since at least March 2026; it used custom Bash scripts to steal temporary cloud credentials, exfiltrated digital asset custody secrets, used Foundry's cast tool to derive Ethereum wallet addresses, deployed the Go-based MikeDor backdoor and an implant impersonating Brazil's SPI instant payment infrastructure, pivoted to Azure DevOps and Kubernetes, and used panels including NEXUS // Scanner, Painel de Emails Entra ID, and Painel Pix for reconnaissance and unauthorized Pix transfers. Rounding out the picture, Palo Alto Networks Unit 42 (reported 2026-09-10 by GBHackers and Cyber Security News) tied two Latin American clusters, CL-CRI-1131 and CL-CRI-1163, by shared SOCKS5 relay infrastructure and revealed the operators used commercial LLMs (Claude and GPT-4.1) behind an exposed self-hosted NextChat interface to generate and troubleshoot post-exploitation scripts. CL-CRI-1131 hit a transportation organization, Mexican federal ministries, and water utilities in Mexico and Ecuador using living-off-the-land batch scripting and Volume Shadow Copies…

  • Breeze Comet (formerly UNC5669) is a financially motivated, Portuguese-speaking e-crime group targeting Brazilian financial services, retail, and e-commerce; one THN report dates its activity to September 2023 while another says since 2024.
  • Per THN, Breeze Comet aligns with Unit 42's CL-CRI-1163, CrowdStrike's Plump Spider, and Trend Micro's SHADOW-AETHER-064.
  • Breeze Comet initial access: password spraying, vishing impersonating IT support to install RMM tools like AnyDesk, WhatsApp social engineering, and exploitation of vulnerable JBoss AS servers for web shell deployment.
  • Breeze Comet tooling: Rust-based COBALTSPIN tunneler; custom backdoors LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM; compromised government websites used as C2; logs cleared after attacks; persistence evolved from RMM tools to Kubernetes…
  • Breeze Comet executes hundreds of fraudulent transactions via Pix, STR, and Boleto payment rails requiring mTLS credentials and AD/cloud access; at least one heist yielded tens of thousands of dollars; infrastructure suggests expansion…
  • CrowdStrike tracks Slim Spider, a previously undocumented financially motivated group attacking Brazilian financial institutions since at least March 2026.
  • Slim Spider used custom Bash scripts to steal temporary cloud credentials, exfiltrated digital asset custody secrets, and used Foundry's cast tool to derive Ethereum wallet addresses.
  • Slim Spider deployed the Go-based MikeDor backdoor and an implant impersonating Brazil's SPI instant payment infrastructure, and pivoted to Azure DevOps and Kubernetes clusters.

Coverage timeline

  1. · 8d ago
    The Hacker News· 82
    Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

    Google/Mandiant profile Breeze Comet, a Brazil-based e-crime group executing fraudulent Pix and STR payment transactions at banks, retailers, and fintechs.