Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Brazilian Financial Firms Targeted by Slim Spider for Crypto Theft

Brazilian Financial Firms Targeted by Slim Spider for Crypto Theft

Posted on September 8, 2026 By CWS

A newly identified cyber threat group, known as Slim Spider, has been actively targeting Brazilian financial institutions since March 2026. This group, tracked by the cybersecurity firm CrowdStrike, has shown a sophisticated understanding of Brazil’s financial systems, including the Pix instant payment service and various digital asset platforms.

Intricate Attacks on Financial Infrastructure

Slim Spider’s activities involve complex, multi-stage intrusions aimed at cryptocurrency holdings and instant payment accounts within Brazilian financial institutions. The group has developed custom Bash scripts to infiltrate cloud environments and extract sensitive credentials related to digital assets. This method involves querying cloud instance metadata to capture temporary cloud credentials.

Once inside the cloud environment, Slim Spider enumerates secrets in the cloud’s credential manager. They utilize the ‘sed’ command to clone and modify scripts for extracting credentials, particularly those tied to digital assets. Their strategy includes invoking ‘cast’, a component of the Foundry Ethereum developer toolkit, to derive wallet addresses from stolen private keys, bypassing third-party libraries to avoid detection.

Techniques and Tools Employed

Slim Spider has been observed deploying backdoors disguised as legitimate infrastructure binaries to maintain stealth in cloud container environments. The group further exploits compromised credentials to access Azure DevOps, running malicious pipelines that deploy implants across managed Kubernetes clusters. These implants attempt to mimic legitimate processes such as Brazil’s Sistema de Pagamentos Instantâneos (SPI).

Additionally, CrowdStrike identified several web-based panels linked to Slim Spider, which automate and streamline their operations. These include the NEXUS // Scanner for endpoint scanning, an email reconnaissance panel, and a transaction panel for unauthorized Pix transfers. The group has also utilized a Go-based backdoor, MikeDor, to collect sensitive data from compromised systems.

Broader Implications and Emerging Threats

The actions of Slim Spider highlight a growing trend in the cybercrime landscape, where threat actors are increasingly targeting the cloud infrastructure and credentials closely linked to high-value financial assets. The potential financial damage for victims is significant, with the theft of cryptocurrency custody credentials posing a severe risk.

Compounding this threat is the rise of another group, Breeze Comet, which has been infiltrating Brazilian financial systems since 2024. This group, also known as CL-CRI-1163 or Plump Spider, exploits payment infrastructure to execute fraudulent transactions. Their operations extend beyond Brazil, with breaches reported in other regions, indicating a broader shift in cybercriminal tactics.

Both groups’ focus on Pix underscores its prominence as a target for cybercriminals. As Brazilian financial systems evolve, the need for robust cybersecurity measures becomes increasingly urgent to protect against these sophisticated threats.

In conclusion, the activities of Slim Spider and Breeze Comet signal a transformative period in Latin American cybercrime, moving from retail fraud to direct attacks on core financial systems. Organizations must adapt to these evolving threats to safeguard their digital assets and financial operations.

The Hacker News Tags:Brazil, Brazilian banks, Breeze Comet, cloud credentials, cloud security, Cryptocurrency, cyber threat, Cybercrime, Cybersecurity, digital assets, Ethereum, financial institutions, Hacking, Pix, Slim Spider

Post navigation

Previous Post: Mars Security Unveils Instant Threat Detection Engine
Next Post: Unseen Threats: How Hidden Prompts Manipulate AI

Related Posts

June 2026 Android Update Fixes 124 Security Issues June 2026 Android Update Fixes 124 Security Issues The Hacker News
Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery The Hacker News
OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity OpenAI Unveils GPT-5.4-Cyber for Enhanced Cybersecurity The Hacker News
Liquid Network Hackers Return Most Bitcoin, M Still Held Liquid Network Hackers Return Most Bitcoin, $47M Still Held The Hacker News
Apache HTTP/2 Vulnerability Exposes Systems to RCE and DoS Apache HTTP/2 Vulnerability Exposes Systems to RCE and DoS The Hacker News
Critical WordPress Flaw Allows Code Execution Critical WordPress Flaw Allows Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fortinet Flaw Enables Man-in-the-Middle Attacks
  • Hackers Return $263M Stolen from Liquid Network
  • ChatGPT Vulnerability Exposed User Data via Hidden Channel
  • Claude Mythos AI Completes Cyber Kill Chain Autonomously
  • Unseen Threats: How Hidden Prompts Manipulate AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fortinet Flaw Enables Man-in-the-Middle Attacks
  • Hackers Return $263M Stolen from Liquid Network
  • ChatGPT Vulnerability Exposed User Data via Hidden Channel
  • Claude Mythos AI Completes Cyber Kill Chain Autonomously
  • Unseen Threats: How Hidden Prompts Manipulate AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark