BREEZE COMET Threat Actor Targets Brazilian Financial Sector with Sophisticated Attacks

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

BREEZE COMET: A Rising Threat to Brazil’s Financial Sector

In 2024, Mandiant began investigating a series of cyber compromises targeting Brazilian financial services, retail, and eCommerce sectors. The Google Threat Intelligence Group (GTIG) has since identified this activity as being orchestrated by a financially motivated threat actor known as BREEZE COMET (formerly UNC5669). This group specializes in manipulating payment systems and banking software to execute fraudulent transfers, posing a significant risk to Brazil’s financial infrastructure. Their operations have been linked to other known campaigns, such as Plump Spider and SHADOW-AETHER-064.

Operational Tactics and Evolving Techniques

BREEZE COMET’s tactics have evolved significantly, utilizing a customized malware suite and compromised, trusted websites to facilitate initial access, command and control (C2), and interaction with financial software and payment APIs. Their operational infrastructure suggests an intent to expand beyond Brazil into other Latin American and African countries. Notably, there is evidence that BREEZE COMET is leveraging generative artificial intelligence (AI) to enhance their malware development, potentially increasing the scale and sophistication of their attacks.

The group primarily targets organizations authorized to conduct transactions through various banking software and payment systems, including Pix, STR, and Boleto. Their objectives necessitate:

  • Access to the National Financial System Network (Rede Nacional do Setor Financeiro, RSFN) through an authorized entity.
  • Access to mTLS credentials for sending authenticated transactional orders.
  • Persistent access to multiple accounts within targeted organizations’ Active Directory and cloud environments.
  • A comprehensive understanding of the organization’s transfer processing procedures and anti-fraud systems.

Initial Compromise and Establishing Footholds

BREEZE COMET employs various methods for initial access. Early on, they utilized password spraying and social engineering tactics, including impersonating IT support teams to convince users to install Remote Monitoring and Management (RMM) tools like AnyDesk. In mid-2025, GTIG observed the group using compromised Brazilian government websites to stage RMM tools and infostealers disguised as legitimate documents. This approach allowed them to avoid detection by leveraging trusted infrastructure.

Additionally, BREEZE COMET has been observed connecting rogue hardware devices directly into retail networks, establishing footholds that facilitate lateral movement within targeted environments. They have also exploited vulnerabilities in JBoss AS servers to gain initial access, further demonstrating their adaptability and resourcefulness.

Privilege Escalation and Lateral Movement

Once inside a network, BREEZE COMET employs publicly available reconnaissance tools and custom malware to escalate privileges and conduct internal reconnaissance. They specifically target development and cloud environments, mining continuous integration and continuous delivery (CI/CD) systems for sensitive credentials and tokens. Their custom scripts are designed to search for critical mTLS credentials and administrative certificates necessary for authenticating against core banking systems.

To navigate through segmented financial networks, BREEZE COMET utilizes hijacked service accounts to initiate unauthorized Remote Desktop Protocol (RDP) sessions and execute commands via SMB file shares. They have also deployed specialized routing malware, known as COBALTSPIN, which operates as a lightweight network tunneler. This malware enables them to maintain persistent access to financial API infrastructure while bypassing internal firewalls, thus facilitating lateral movement without triggering detection mechanisms.

The implications of BREEZE COMET’s activities are profound, as their sophisticated methods pose a significant threat to the integrity of Brazil’s financial systems. Organizations within the financial sector must remain vigilant and adopt robust security measures to defend against such evolving threats.

For further insights into BREEZE COMET’s tactics and recommendations for mitigation, refer to the detailed analysis provided by the Google Threat Intelligence Group here.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cisco Patches Critical Nexus 9000 Vulnerability Allowing Remote Code Execution as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker...

Dropbox Reports Compromise of 5,000 Accounts Due to Legacy Login Vulnerability

Dropbox has reported that approximately 5,000 accounts were compromised last month due to a legacy login vulnerability associated with Lenovo IDs. This breach allowed...

Maine Teen Becomes First Minor Federally Charged for Crimes Linked to Violent Extremist Group 764

The FBI has announced that a 17-year-old from Maine is the first minor to be federally charged and adjudicated for crimes related to their...

GnuPG Vulnerability Allows Potential Bypass of Message Integrity Checks

GnuPG Vulnerability Allows Potential Bypass of Message Integrity Checks A recently discovered vulnerability in GnuPG has raised concerns regarding the integrity of messages encrypted with...