news.mlab.sh
Back to the feed
threat-intel

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

High
Summary

The threat actor Breeze Comet (formerly UNC5669), operating out of Brazil since 2023, has been aggressively targeting financial services, retail, and e-commerce organizations in Brazil and expanding into Latin America and Africa. They employ a sophisticated, evolving malware suite and tactics, including RMM tool deployment, web shell exploitation, and leveraging compromised websites to gain initial access and conduct hundreds of fraudulent transactions. The group’s tactics are shifting from retail banking fraud to direct intrusions into core financial infrastructure, utilizing LLM-assisted malware development for faster tradecraft and increased operational efficiency.

Google Threat Intelligence Group (GTIG) and Mandiant teams have identified Breeze Comet (formerly UNC5669) as a financially motivated threat actor operating primarily in Brazil since September 2023. The group specializes in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers, and their tactics have evolved significantly over time. Initial access is frequently achieved through password spraying and impersonating IT support teams via WhatsApp, persuading victims to install Remote Monitoring and Management (RMM) tools like AnyDesk.

Alternatively, the group targets vulnerable JBoss AS servers to deploy web shells, which are then used to deliver additional tooling, including Chisel and other proxy utilities, for follow-on exploitation. Breeze Comet’s primary targets are organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto, encompassing banks, payment processors, retailers, and fintech providers.

To achieve its goals, Breeze Comet requires four key elements: access to the National Financial System Network (RSFN) through an entity with existing access; mTLS credentials for sending authenticated payloads to Pix or STR; access to multiple accounts in targeted organizations’ Active Directory and cloud environments; and a deep understanding of an organization’s transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.

Notable tactics include using compromised Brazilian small government websites to stage RMM tools, infostealers disguised as tax documents, and backdoors like XWorm. The group also connects rogue hardware devices directly into retail store networks to establish footholds and move laterally, downloading Netcat and custom scripts to retrieve post-exploitation frameworks. They utilize tools like Impacket, ADRecon, and ADVipscan, alongside custom LDAP brute-forcing utility REALBREEZE, to conduct internal reconnaissance and escalate privileges.

Lateral movement is achieved by initiating RDP sessions and executing commands via SMB network file shares, deploying COBALTSPIN, a Rust-based routing malware that operates as a network tunneler to communicate with and maintain persistent network access to financial API infrastructure. COBALTSPIN routes network traffic securely back and forth between the C2 and internal targets, bypassing firewalls.

Breeze Comet’s persistence mechanisms have evolved from deploying commercial RMM tools in 2024 to deploying malicious Kubernetes pods a year later and stealing cloud secrets by exfiltrating them to public-facing notepad websites like “dontpad[.]com.” They also utilize multiple custom backdoors, including LIGHTPAINT (Java), MILDFROST (passive Java JAR), and KICKPLATE (Nim), to provide redundant access and conceal their activities. To prevent detection and removal, the threat actor executes PowerShell commands to disable Windows Defender’s real-time monitoring.

Finally, COBALTSPIN and compromised privileged accounts are used to access core financial applications and execute hundreds of fraudulent transactions, with event logs cleared to minimize the forensic footprint and conceal API interactions. The presence of verbose explanatory comments and standardized execution headers indicates the use of a large language model (LLM) to compress the malware development lifecycle, a trend identified by Trend Micro in May 2026, which also found scripts demonstrating “descriptions of self-reasoning and autonomous decision-making processes.”

Read the full article at The Hacker News