BREEZE COMET Hackers Use AI Malware to Target Brazil Banks
Key Takeaways The BREEZE COMET threat group is actively targeting Brazilian financial institutions, retail, and e-commerce sectors since 2024. This financially motivated actor, previously known as...
Key Takeaways
- The BREEZE COMET threat group is actively targeting Brazilian financial institutions, retail, and e-commerce sectors since 2024.
- This financially motivated actor, previously known as UNC5669, uses a blend of custom malware and generative AI to facilitate fraudulent financial transfers.
- Instead of individual consumers, BREEZE COMET focuses on compromising the systems and accounts responsible for processing financial transactions within organizations.
- The attacks leverage various initial access methods, including password spraying, social engineering (vishing), compromised legitimate websites, and direct network infiltration via rogue hardware.
- Defenders face reduced response times due to AI-assisted automation in network discovery, credential validation, and data exfiltration.
A sophisticated cybercrime group, dubbed BREEZE COMET and previously tracked as UNC5669, is launching a targeted campaign against Brazilian financial institutions and payment processors. Unlike typical attacks focusing on individual consumers, this financially motivated threat actor aims to infiltrate the core systems that facilitate money movement, seeking to execute fraudulent transfers through legitimate financial channels. The campaign has impacted financial services, retail, and e-commerce organizations throughout 2024.
Table Of Content
Analysts at Google Cloud have identified the group’s innovative use of custom malware combined with generative AI. This potent combination significantly accelerates various stages of the attack lifecycle, including network reconnaissance, testing stolen credentials, lateral movement within systems, and preparing data for exfiltration. By streamlining these processes, the AI-assisted approach provides a more direct and efficient path to payment fraud, transforming conventional intrusions into rapid, high-impact financial compromises. This activity, detailed in a report by Google Cloud, shows overlaps with operations publicly attributed to groups known as Plump Spider and SHADOW-AETHER-064. Researchers also caution that the observed infrastructure patterns suggest a potential expansion of BREEZE COMET’s operations across Latin America and into Africa.
BREEZE COMET Leverages AI-Assisted Malware
The attackers specifically target organizations authorized to initiate transactions through banking software, APIs, and payment systems like Pix, STR, and Boleto. Achieving their objectives requires gaining access to the National Financial System Network, obtaining authenticated mTLS credentials, compromising privileged accounts, and understanding internal transfer controls.
Initial Access and Lateral Movement
Early phases of the intrusions involved tactics such as password spraying and voice phishing, where attackers impersonated IT support personnel to trick victims into installing remote management tools. More recent campaigns have utilized compromised municipal websites to host malicious lures, often disguised as tax documents or receipts, to facilitate initial access.
The group has also demonstrated an ability to connect rogue hardware directly to retail networks, subsequently moving deeper into internal systems. This strategy highlights a growing trend of hijacked finance mailbox fraud, where established trusted access can be exploited to authorize illicit payment alterations.
Advanced Tooling and AI Integration
BREEZE COMET actively scans development and cloud environments for critical credentials, including pipeline access, API keys, cloud tokens, certificates, and mTLS materials. Their custom tool, REALBREEZE, is designed to brute-force or guess directory credentials. Compromising development secrets can significantly expand the scope of an intrusion, as demonstrated by recent cloud credential theft incidents.
The group employs a suite of sophisticated tools for persistence and command and control. COBALTSPIN, a Rust-based tunneling tool, establishes covert communication by routing traffic through a reverse SOCKS5 proxy over WebSocket connections. Additional backdoors, including LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, provide redundant access. LIGHTPAINT deploys a VPN for network access, while MILDFROST utilizes DNS for a stealthier fallback communication channel. KICKPLATE manipulates startup settings and services for persistence, and BOATBEAM conceals its traffic by masquerading as a legitimate HTTPS server.
Crucially, investigators discovered evidence that large language models (LLMs) were used to assist in generating scripts for critical attack phases. These included scripts for network discovery, credential validation, mass malware deployment, victim-specific routing, and data extraction. While AI did not replace human expertise, its application appears to have drastically reduced the time required to customize and deploy tools tailored to specific victims. This acceleration means that organizations may have a significantly shorter window between an initial suspicious login and the execution of a fraudulent payment, particularly when multiple compromised environments are under the control of a single operator.
Rapid Fraud Execution
The final stage of the fraud can unfold with alarming speed. In one documented instance, BREEZE COMET leveraged COBALTSPIN and compromised privileged accounts to access core financial applications. Within a tight 24 to 48-hour timeframe, the group initiated two distinct waves of hundreds of fraudulent transactions, subsequently clearing logs and deleting directories in an attempt to obscure their activities, as detailed in the Google Cloud blog post.
What You Should Do
- Endpoint Security: Prohibit the installation of unauthorized remote management tools and prevent the execution of software from user-writable directories.
- Social Engineering Awareness: Establish clear protocols for employees to verify unexpected support calls and implement phishing-resistant multi-factor authentication (MFA) with lockout controls for all external portals.
- Network Access Control: For retail and branch networks, implement 802.1X network access control, disable unused switch ports, restrict approved device MAC addresses, and secure network closets to prevent the connection of rogue devices.
- Cloud Security Posture: Enforce the principle of least privilege for Kubernetes service accounts, block privileged containers, and apply strict outbound network policies. Ensure that sensitive information (secrets) is never stored directly in source code or environment files, addressing common Kubernetes misconfiguration security risks.
- Threat Hunting & Monitoring: Actively monitor for unusual PowerShell activity, newly created services, unauthorized startup modifications, DNS tunneling, remote desktop sessions, and suspicious access to payment APIs. Regularly review certificate usage, CI/CD pipeline access, and unexpected proxy traffic.
- Incident Response: In the event of a suspected compromise, immediately isolate affected hosts while preserving all logs for forensic investigation. Do not blindly trust traffic to public-sector domains; always inspect suspicious activity regardless of the domain’s reputation.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec |
Published file indicator |
| SHA-256 | 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a |
Published file indicator |
| SHA-256 | c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a |
Published file indicator |
| SHA-256 | 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb |
Published file indicator |
| SHA-256 | f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f |
Published file indicator |
| SHA-256 | 51fdd83b3737add7f3832bd0ad0b5686
|



No Comment! Be the first one.