Since 2024, Brazilian financial institutions and e-commerce platforms have been under siege by a cybercriminal group known as Breeze Comet, previously identified as UNC5669. This group has been actively engaged in exploiting payment systems and banking software to execute fraudulent transactions, as reported by the Google Threat Intelligence Group and Mandiant.
Impact on Brazilian Financial Systems
Breeze Comet’s activities have been linked to significant financial thefts, with at least one incident involving the loss of tens of thousands of U.S. dollars. This group’s operations overlap with those tracked by CrowdStrike and Trend Micro, known respectively as Plump Spider and SHADOW-AETHER-064. Reports indicate the group operates out of Brazil, having been active since September 2023, and focusing on unauthorized access to internal financial networks.
To gain initial access, Breeze Comet employs tactics such as password spraying and impersonating IT support via phone calls, persuading targets to install Remote Monitoring and Management (RMM) tools like AnyDesk. A notable case in November 2025 involved the group posing as IT support over WhatsApp to trick a victim into installing a PowerShell script under the guise of a corporate application update.
Methods of Intrusion and Exploitation
Breeze Comet’s tactics include exploiting vulnerable JBoss AS servers to deploy web shells, which facilitate further exploitation using tools like Chisel. Their primary targets are entities authorized to conduct transactions through systems like Pix, STR, and Boleto, including banks, fintech companies, and payment processors.
To achieve their objectives, the group must meet several criteria: gaining access to the National Financial System Network (RSFN), obtaining mTLS credentials for authenticated transactions, and compromising accounts within the targeted organizations’ Active Directories and cloud environments. Additionally, they need to understand the target’s financial processes and defenses.
Advanced Techniques and Global Implications
The group’s advanced techniques include using compromised websites to stage RMM tools and malware, deploying rogue hardware in retail networks, and utilizing tools like Impacket and ADRecon for internal reconnaissance. Their methodology has been replicated in countries such as Nigeria, Paraguay, Ghana, and Venezuela, indicating a broader regional threat.
Among their sophisticated tools are custom backdoors like LIGHTPAINT, MILDFROST, and KICKPLATE, designed for persistent access and control. They also use COBALTSPIN, a Rust-based malware, to maintain network access via a SOCKS5 proxy and evade detection.
In the final stage of their operations, Breeze Comet uses COBALTSPIN and compromised accounts to perform fraudulent transactions while erasing logs to cover their tracks. Their use of large language models (LLMs) suggests a streamlined development process, posing a growing challenge for cybersecurity defenses.
This evolution from traditional retail fraud to direct financial intrusions highlights a significant shift in the Latin American cybercrime landscape. As these groups increasingly leverage AI tools, the need for robust and adaptive cybersecurity measures becomes ever more critical.
