Brazil’s financial sector is confronting a sophisticated cyber threat as AI-driven malware orchestrated by a group known as BREEZE COMET targets banking systems. Unlike traditional cybercriminals who focus on individual accounts, this group exploits the infrastructure that handles financial transactions. The group’s operations, ongoing since 2024, have already disrupted several financial services and e-commerce platforms.
BREEZE COMET’s Advanced Tactics
The group’s primary objective is to gain trusted access to financial systems and execute unauthorized transfers via legitimate channels. Their tactics include password spraying, impersonating IT support through phone calls, and using compromised public websites. Google Cloud researchers have identified the use of custom malware in conjunction with generative AI, which streamlines network exploration, credential testing, and data theft.
This method provides a more direct path to financial fraud, enhancing the group’s ability to execute their activities quickly and efficiently. The operation shares characteristics with other known cybercrime entities, such as Plump Spider, suggesting a wider reach across Latin America and Africa.
Infiltration Techniques and Tools
BREEZE COMET’s attacks focus on organizations equipped to handle transactions via banking software and systems like Pix and Boleto. To gain access, they require authenticated network credentials and privileged account information. Initially, they employed password spraying and voice phishing, urging victims to install remote management tools. Subsequently, they used compromised websites to host malicious files disguised as legitimate documents.
They further infiltrated networks by connecting rogue devices to retail systems, facilitating unauthorized access to internal systems. Their malware arsenal, including tools like REALBREEZE and COBALTSPIN, allows them to navigate and exploit network vulnerabilities, while AI-driven scripts expedite their operations.
Defense Strategies for Financial Institutions
To combat such threats, financial institutions must strengthen defenses by blocking unapproved remote tools and ensuring software cannot run in writable folders. Employees should be trained to verify unexpected support communications, and robust multi-factor authentication should be enforced on external portals.
Physical and digital safeguards are crucial for retail and branch networks, including deploying 802.1X network access control and securing network infrastructure. Additionally, cloud environments should adopt the principle of least privilege, secure service accounts, and monitor for abnormal activities like DNS tunneling and unauthorized API access.
As the digital landscape evolves, the importance of comprehensive security measures becomes evident. By staying alert to the latest threat indicators and adopting proactive security measures, organizations can mitigate the risks posed by advanced cyber threats like those from BREEZE COMET.
