Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
FBI and CrowdStrike Disrupt Sality Botnet
September 2, 2026
Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token
September 2, 2026
BREEZE COMET Hackers Use AI Malware to Target Brazil Banks
September 2, 2026
Home/Threats/BREEZE COMET Hackers Use AI Malware to Target Brazil Banks
Threats

BREEZE COMET Hackers Use AI Malware to Target Brazil Banks

Key Takeaways The BREEZE COMET threat group is actively targeting Brazilian financial institutions, retail, and e-commerce sectors since 2024. This financially motivated actor, previously known as...

Sarah simpson
Sarah simpson
September 2, 2026 4 Min Read
2 0

Key Takeaways

  • The BREEZE COMET threat group is actively targeting Brazilian financial institutions, retail, and e-commerce sectors since 2024.
  • This financially motivated actor, previously known as UNC5669, uses a blend of custom malware and generative AI to facilitate fraudulent financial transfers.
  • Instead of individual consumers, BREEZE COMET focuses on compromising the systems and accounts responsible for processing financial transactions within organizations.
  • The attacks leverage various initial access methods, including password spraying, social engineering (vishing), compromised legitimate websites, and direct network infiltration via rogue hardware.
  • Defenders face reduced response times due to AI-assisted automation in network discovery, credential validation, and data exfiltration.

A sophisticated cybercrime group, dubbed BREEZE COMET and previously tracked as UNC5669, is launching a targeted campaign against Brazilian financial institutions and payment processors. Unlike typical attacks focusing on individual consumers, this financially motivated threat actor aims to infiltrate the core systems that facilitate money movement, seeking to execute fraudulent transfers through legitimate financial channels. The campaign has impacted financial services, retail, and e-commerce organizations throughout 2024.

Table Of Content

  • Key Takeaways
  • BREEZE COMET Leverages AI-Assisted Malware
  • Initial Access and Lateral Movement
  • Advanced Tooling and AI Integration
  • Rapid Fraud Execution
  • What You Should Do
  • Indicators of Compromise (IoCs)

Analysts at Google Cloud have identified the group’s innovative use of custom malware combined with generative AI. This potent combination significantly accelerates various stages of the attack lifecycle, including network reconnaissance, testing stolen credentials, lateral movement within systems, and preparing data for exfiltration. By streamlining these processes, the AI-assisted approach provides a more direct and efficient path to payment fraud, transforming conventional intrusions into rapid, high-impact financial compromises. This activity, detailed in a report by Google Cloud, shows overlaps with operations publicly attributed to groups known as Plump Spider and SHADOW-AETHER-064. Researchers also caution that the observed infrastructure patterns suggest a potential expansion of BREEZE COMET’s operations across Latin America and into Africa.

BREEZE COMET Leverages AI-Assisted Malware

The attackers specifically target organizations authorized to initiate transactions through banking software, APIs, and payment systems like Pix, STR, and Boleto. Achieving their objectives requires gaining access to the National Financial System Network, obtaining authenticated mTLS credentials, compromising privileged accounts, and understanding internal transfer controls.

Initial Access and Lateral Movement

Early phases of the intrusions involved tactics such as password spraying and voice phishing, where attackers impersonated IT support personnel to trick victims into installing remote management tools. More recent campaigns have utilized compromised municipal websites to host malicious lures, often disguised as tax documents or receipts, to facilitate initial access.

The group has also demonstrated an ability to connect rogue hardware directly to retail networks, subsequently moving deeper into internal systems. This strategy highlights a growing trend of hijacked finance mailbox fraud, where established trusted access can be exploited to authorize illicit payment alterations.

Advanced Tooling and AI Integration

BREEZE COMET actively scans development and cloud environments for critical credentials, including pipeline access, API keys, cloud tokens, certificates, and mTLS materials. Their custom tool, REALBREEZE, is designed to brute-force or guess directory credentials. Compromising development secrets can significantly expand the scope of an intrusion, as demonstrated by recent cloud credential theft incidents.

The group employs a suite of sophisticated tools for persistence and command and control. COBALTSPIN, a Rust-based tunneling tool, establishes covert communication by routing traffic through a reverse SOCKS5 proxy over WebSocket connections. Additional backdoors, including LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, provide redundant access. LIGHTPAINT deploys a VPN for network access, while MILDFROST utilizes DNS for a stealthier fallback communication channel. KICKPLATE manipulates startup settings and services for persistence, and BOATBEAM conceals its traffic by masquerading as a legitimate HTTPS server.

Crucially, investigators discovered evidence that large language models (LLMs) were used to assist in generating scripts for critical attack phases. These included scripts for network discovery, credential validation, mass malware deployment, victim-specific routing, and data extraction. While AI did not replace human expertise, its application appears to have drastically reduced the time required to customize and deploy tools tailored to specific victims. This acceleration means that organizations may have a significantly shorter window between an initial suspicious login and the execution of a fraudulent payment, particularly when multiple compromised environments are under the control of a single operator.

Rapid Fraud Execution

The final stage of the fraud can unfold with alarming speed. In one documented instance, BREEZE COMET leveraged COBALTSPIN and compromised privileged accounts to access core financial applications. Within a tight 24 to 48-hour timeframe, the group initiated two distinct waves of hundreds of fraudulent transactions, subsequently clearing logs and deleting directories in an attempt to obscure their activities, as detailed in the Google Cloud blog post.

What You Should Do

  • Endpoint Security: Prohibit the installation of unauthorized remote management tools and prevent the execution of software from user-writable directories.
  • Social Engineering Awareness: Establish clear protocols for employees to verify unexpected support calls and implement phishing-resistant multi-factor authentication (MFA) with lockout controls for all external portals.
  • Network Access Control: For retail and branch networks, implement 802.1X network access control, disable unused switch ports, restrict approved device MAC addresses, and secure network closets to prevent the connection of rogue devices.
  • Cloud Security Posture: Enforce the principle of least privilege for Kubernetes service accounts, block privileged containers, and apply strict outbound network policies. Ensure that sensitive information (secrets) is never stored directly in source code or environment files, addressing common Kubernetes misconfiguration security risks.
  • Threat Hunting & Monitoring: Actively monitor for unusual PowerShell activity, newly created services, unauthorized startup modifications, DNS tunneling, remote desktop sessions, and suspicious access to payment APIs. Regularly review certificate usage, CI/CD pipeline access, and unexpected proxy traffic.
  • Incident Response: In the event of a suspected compromise, immediately isolate affected hosts while preserving all logs for forensic investigation. Do not blindly trust traffic to public-sector domains; always inspect suspicious activity regardless of the domain’s reputation.

Indicators of Compromise (IoCs)

Type Indicator Description
SHA-256 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec Published file indicator
SHA-256 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a Published file indicator
SHA-256 c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a Published file indicator
SHA-256 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb Published file indicator
SHA-256 f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f Published file indicator
SHA-256 51fdd83b3737add7f3832bd0ad0b5686

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Claude AI Creates Pre-Auth RCE Exploit for WAGO PLCs

Next Post

Cleo Harmony Flaw Lets Remote Attackers Escalate Privileges via JWT Refresh Token

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
FreeRDP Patches 22 Vulnerabilities, Including Critical RCE Flaws
September 2, 2026
Critical LiteLLM Admin API Flaw Lets Attackers Steal Secrets, Target AI Gateway Servers
September 2, 2026
Fox-Linked Hackers Disable Microsoft Defender With Fake Software
September 2, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us