Breeze Comet and Slim Spider Hit Brazilian Finance; Unit 42 Reports LLM-Assisted Intrusions Using Claude and GPT-4.1
Google Threat Intelligence Group/Mandiant, CrowdStrike and Palo Alto Networks Unit 42 describe financially motivated campaigns against Brazilian and wider Latin American financial infrastructure: Breeze Comet (formerly UNC5669) executes hundreds of fraudulent…
Dark Reading first reported (2026-09-03) that 'Breeze Comet', described as Brazil's most sophisticated threat group, was compromising Brazil's financial systems and reportedly moving stolen funds directly to the attackers, with the campaign reportedly extending to global financial systems but with few technical details or attribution evidence disclosed. Google Threat Intelligence Group and Mandiant then profiled the actor (The Hacker News, 2026-09-08T11:22Z) as Breeze Comet (formerly UNC5669), a financially motivated, Brazil-based group targeting Brazilian financial services, retail and e-commerce, which clears logs after executing hundreds of fraudulent transactions through the Pix, STR and Boleto payment systems - rails requiring mTLS credentials and Active Directory/cloud access; at least one heist yielded tens of thousands of dollars. Sources disagree on when the group became active (September 2023 in the Mandiant profile versus 2024 in a later The Hacker News report citing the same vendors) and on scope (Dark Reading's global financial systems versus Mandiant's infrastructure-based assessment of expansion toward Latin America and Africa). Per the Mandiant profile, initial access combines password spraying, vishing calls impersonating IT support that install RMM tools such as AnyDesk, WhatsApp social engineering, and exploitation of vulnerable JBoss AS servers for web shell deployment; the group uses compromised government websites as C2 and deploys the Rust-based COBALTSPIN tunneler plus custom backdoors LIGHTPAINT, MILDFROST, KICKPLATE and BOATBEAM, with persistence evolving from RMM tools to Kubernetes pods and secret exfiltration via dontpad.com. Vendor naming: one report equates Breeze Comet with Unit 42's CL-CRI-1163 while another describes an overlap; CrowdStrike tracks the activity as Plump Spider and Trend Micro as SHADOW-AETHER-064; one report describes the group as Portuguese-speaking. In a separate disclosure (The Hacker News, 2026-09-08T16:20Z), CrowdStrike introduced Slim Spider, a previously undocumented financially motivated group attacking Brazilian financial institutions since at least March 2026: it stole temporary cloud credentials with custom Bash scripts, exfiltrated digital asset custody secrets, used Foundry's cast tool to derive Ethereum wallet addresses, deployed the Go backdoor MikeDor and an implant impersonating Brazil's SPI instant payment infrastructure, pivoted to Azure DevOps and Kubernetes clusters, and used panels…
- Dark Reading (2026-09-03) reported that 'Breeze Comet', described as Brazil's most sophisticated threat group, is compromising Brazil's financial systems with funds reportedly moved directly to attackers; it said the campaign reportedly…
- Google Threat Intelligence Group and Mandiant (The Hacker News, 2026-09-08T11:22Z) profile Breeze Comet (formerly UNC5669) as a financially motivated, Brazil-based group targeting financial services, retail and e-commerce; they date its…
- Breeze Comet clears logs after executing hundreds of fraudulent transactions through the Pix, STR and Boleto payment systems, which require mTLS credentials and Active Directory/cloud access; at least one heist yielded tens of thousands of…
- Initial access combines password spraying, vishing impersonating IT support to install RMM tools such as AnyDesk, WhatsApp social engineering, and exploitation of vulnerable JBoss AS servers for web shell deployment.
- Tooling includes the Rust-based COBALTSPIN tunneler and custom backdoors LIGHTPAINT, MILDFROST, KICKPLATE and BOATBEAM; compromised government websites serve as C2; persistence evolved from RMM tools to Kubernetes pods with secret…
- Scope disagreement: Mandiant's infrastructure analysis suggests expansion toward Latin America and Africa, whereas Dark Reading characterized the campaign as reaching global financial systems.
- Vendor naming overlaps: one report equates Breeze Comet with Unit 42's CL-CRI-1163 while another describes an overlap; CrowdStrike tracks it as Plump Spider and Trend Micro as SHADOW-AETHER-064; one report describes the group as…
- CrowdStrike (The Hacker News, 2026-09-08T16:20Z) introduced Slim Spider, a previously undocumented financially motivated group attacking Brazilian financial institutions since at least March 2026.
Coverage timelineoldest first · each row is one article
- · 12d ago'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Dark Reading· 55
Threat group 'Breeze Comet' is attacking Brazil's financial systems and reportedly stealing funds directly, per Dark Reading threat intelligence.