news.mlab.sh
Back to the feed
threat-intel

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

High
Summary

A Brazil-based cybercrime group, known as Slim Spider, has been linked to a multi-stage intrusion campaign targeting Brazilian financial institutions since March 2026. The group leverages sophisticated cloud attack techniques, including custom Bash scripts to steal credentials, and employs tools like MikeDor to harvest sensitive information. They’ve been observed deploying backdoors, utilizing compromised credentials via Azure DevOps, and exploiting tools like NEXUS // Scanner and Painel Pix to steal cryptocurrency assets and execute fraudulent transactions, mirroring the tactics of another group, Breeze Comet, who are also targeting Brazilian financial systems. This represents a significant shift in the region's cybercrime landscape, moving beyond retail fraud to directly attacking core payment infrastructure.

A previously undocumented financially motivated threat actor, operating under the name Slim Spider, has been linked to attacks targeting Brazilian financial institutions since March 2026. Cybersecurity company CrowdStrike is tracking this activity cluster. Slim Spider demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities’ cloud environments.

As part of a multi-stage intrusion, Slim Spider developed custom Bash scripts to query cloud instance metadata and steal temporary cloud credentials over socket connections. Upon gaining access to a financial institution’s cloud environment, the threat actor enumerated all available secrets stored in the cloud credential manager and used the "sed" command to clone and modify secret-extracting scripts, specifically targeting credentials associated with digital financial assets. They then invoked cast, a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key.

To avoid detection, Slim Spider implemented cloud-native cryptographic signing directly via OpenSSL within their Bash scripts, a deliberate choice reflecting sophisticated operational security awareness and a nuanced understanding of cloud environments. The group moved to establish access to nodes running in a cloud container service cluster, deploying backdoors mimicking infrastructure-related binaries to blend with legitimate tooling and fly under the radar.

Slim Spider pivoted to Azure DevOps, likely using compromised credentials, to run malicious pipelines that deployed additional implants across a managed Kubernetes cluster. One of the implants was named "spi," an attempt to impersonate Sistema de Pagamentos Instantâneos (SPI), which refers to the central digital infrastructure that processes Pix payments in Brazil. The group also utilizes web-based panels to automate and streamline different aspects of the attack chain, including NEXUS // Scanner (using Ollama to slot endpoints into categories like fintech, banking, payment, and cryptocurrency) and Painel Pix (designed to execute bulk unauthorized Pix transfers).

CrowdStrike discovered an exposed command-and-control (C2) panel connected to the threat actor, displaying several compromised hosts from various Brazil-based banks and fintech organizations, and likely exfiltrating archive files. Another key tool in Slim Spider’s arsenal is MikeDor, a Go-based backdoor capable of harvesting sensitive information and monitoring user activities.

Google Threat Intelligence Group (GTIG) and Mandiant have linked the Portuguese-speaking hacking group to Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064), who are also infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions. Breeze Comet has attempted to replicate this formula in other regions, hacking municipal websites in countries like Nigeria, Paraguay, Ghana, and Venezuela. The ultimate goal is to obtain access to the financial applications that the breached organizations use to make payments, including Pix, Boleto, and the Reserves Transfer System (STR), and execute hundreds of fraudulent transactions.

The targeting of Pix by two different threat actors highlights how the most widely used payment method in Brazil has become a lucrative target across operating systems. This shift from opportunistic retail banking fraud to directly attacking core payment infrastructure represents a notable evolution in the region’s cybercrime landscape.

Read the full article at The Hacker News