A newly identified cyber threat group, known as Slim Spider, has been actively targeting Brazilian financial institutions since March 2026. This group, tracked by the cybersecurity firm CrowdStrike, has shown a sophisticated understanding of Brazil’s financial systems, including the Pix instant payment service and various digital asset platforms.
Intricate Attacks on Financial Infrastructure
Slim Spider’s activities involve complex, multi-stage intrusions aimed at cryptocurrency holdings and instant payment accounts within Brazilian financial institutions. The group has developed custom Bash scripts to infiltrate cloud environments and extract sensitive credentials related to digital assets. This method involves querying cloud instance metadata to capture temporary cloud credentials.
Once inside the cloud environment, Slim Spider enumerates secrets in the cloud’s credential manager. They utilize the ‘sed’ command to clone and modify scripts for extracting credentials, particularly those tied to digital assets. Their strategy includes invoking ‘cast’, a component of the Foundry Ethereum developer toolkit, to derive wallet addresses from stolen private keys, bypassing third-party libraries to avoid detection.
Techniques and Tools Employed
Slim Spider has been observed deploying backdoors disguised as legitimate infrastructure binaries to maintain stealth in cloud container environments. The group further exploits compromised credentials to access Azure DevOps, running malicious pipelines that deploy implants across managed Kubernetes clusters. These implants attempt to mimic legitimate processes such as Brazil’s Sistema de Pagamentos Instantâneos (SPI).
Additionally, CrowdStrike identified several web-based panels linked to Slim Spider, which automate and streamline their operations. These include the NEXUS // Scanner for endpoint scanning, an email reconnaissance panel, and a transaction panel for unauthorized Pix transfers. The group has also utilized a Go-based backdoor, MikeDor, to collect sensitive data from compromised systems.
Broader Implications and Emerging Threats
The actions of Slim Spider highlight a growing trend in the cybercrime landscape, where threat actors are increasingly targeting the cloud infrastructure and credentials closely linked to high-value financial assets. The potential financial damage for victims is significant, with the theft of cryptocurrency custody credentials posing a severe risk.
Compounding this threat is the rise of another group, Breeze Comet, which has been infiltrating Brazilian financial systems since 2024. This group, also known as CL-CRI-1163 or Plump Spider, exploits payment infrastructure to execute fraudulent transactions. Their operations extend beyond Brazil, with breaches reported in other regions, indicating a broader shift in cybercriminal tactics.
Both groups’ focus on Pix underscores its prominence as a target for cybercriminals. As Brazilian financial systems evolve, the need for robust cybersecurity measures becomes increasingly urgent to protect against these sophisticated threats.
In conclusion, the activities of Slim Spider and Breeze Comet signal a transformative period in Latin American cybercrime, moving from retail fraud to direct attacks on core financial systems. Organizations must adapt to these evolving threats to safeguard their digital assets and financial operations.
