← All stories
● Covered by 2 sources · 3 reportsMedium impact3 negative

Mandiant Details BREEZE COMET Threat Actor Targeting Brazilian Financial Services

🔄 Updated 23d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • BREEZE COMET targets Brazilian financial services, retail, and eCommerce.
  • The group manipulates payment systems like Pix, STR, and Boleto for fraudulent transfers.
  • BREEZE COMET uses customized malware and compromised websites for access and control.
  • Evidence suggests BREEZE COMET uses generative AI for malware development.
  • BREEZE COMET was formerly known as UNC5669.
  • BREEZE COMET has been active since 2024.
  • BREEZE COMET executed at least one heist worth tens of thousands of U.S. dollars.
  • CrowdStrike tracks BREEZE COMET as Plump Spider.
  • Trend Micro tracks BREEZE COMET as SHADOW-AETHER-064.
  • CrowdStrike states BREEZE COMET is operating out of Brazil.
  • CrowdStrike states BREEZE COMET has been active since September 2023.
  • BREEZE COMET gains initial access via password spraying and voice calls.
  • BREEZE COMET persuades targets to install RMM tools like AnyDesk.
  • BREEZE COMET targets cryptocurrency assets.
  • BREEZE COMET uses custom Bash scripts to steal temporary cloud credentials.
  • BREEZE COMET enumerates secrets in cloud credential managers.
  • BREEZE COMET uses the "sed" command to clone and modify secret-extracting scripts.

Threat Actor Overview

Mandiant, a part of Google Threat Intelligence Group (GTIG), has been investigating a series of compromises affecting Brazilian financial services, retail, and eCommerce organizations since the beginning of 2024. GTIG tracks this activity under the name BREEZE COMET, previously known as UNC5669. This financially motivated threat actor focuses on manipulating payment systems and banking software within Brazil to execute fraudulent transfers. Their operations overlap with activities reported publicly as Plump Spider and SHADOW-AETHER-064.

Tactics and Tools

BREEZE COMET's tactics have evolved to include a customized malware suite and the use of compromised, trusted websites. These websites facilitate initial access, command and control (C2), and interaction with financial software and payment APIs. The group's operational infrastructure indicates a potential intent to expand its footprint into other Latin American and African countries. There is also evidence that BREEZE COMET is utilizing generative artificial intelligence (AI) to support malware development, which could increase the scale, speed, and sophistication of their future operations.

Targeted Systems and Objectives

BREEZE COMET operations specifically target organizations with permissions to conduct transactions through banking software, APIs, and payment systems such as Pix, STR (Brazilian Reserves Transfer System), and Boleto. This includes banks, payment processors, retailers, exchanges, and fintech and banking software providers. To achieve fraudulent transfers, BREEZE COMET requires access to the National Financial System Network (RSFN), mTLS credentials for authenticated transactional orders, persistent access to Active Directory or cloud environments, and an understanding of an organization’s transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.

Updates

🕒 2026-09-08 · new reporting from The Hacker News
  • BREEZE COMET targets cryptocurrency assets.
  • BREEZE COMET uses custom Bash scripts to steal temporary cloud credentials.
  • BREEZE COMET enumerates secrets in cloud credential managers.
  • BREEZE COMET uses the "sed" command to clone and modify secret-extracting scripts.
🕒 2026-09-01 · new reporting from The Hacker News
  • BREEZE COMET was formerly known as UNC5669.
  • BREEZE COMET has been active since 2024.
  • BREEZE COMET executed at least one heist worth tens of thousands of U.S. dollars.
  • CrowdStrike tracks BREEZE COMET as Plump Spider.
  • Trend Micro tracks BREEZE COMET as SHADOW-AETHER-064.
  • CrowdStrike states BREEZE COMET is operating out of Brazil.
  • CrowdStrike states BREEZE COMET has been active since September 2023.
  • BREEZE COMET gains initial access via password spraying and voice calls.
  • BREEZE COMET persuades targets to install RMM tools like AnyDesk.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A new financially motivated threat actor, dubbed Slim Spider by CrowdStrike, has been observed targeting Brazilian financial institutions since March 2026, specifically focusing on cryptocurrency assets and instant payment accounts. The group uses custom Bash scripts to steal temporary cloud credentials and digital asset custody secrets, demonstrating sophisticated operational security and cloud environment understanding.

A financially motivated threat actor, Breeze Comet (formerly UNC5669), has been targeting Brazilian financial services, retail, and e-commerce organizations since 2024. The group manipulates payment systems and banking software to conduct fraudulent transfers, having already executed at least one heist worth tens of thousands of U.S. dollars. This activity impacts a wide range of entities involved in Brazilian payment systems like Pix, STR, and Boleto.

Mandiant, part of Google Threat Intelligence Group, has identified BREEZE COMET (formerly UNC5669) as a financially motivated threat actor actively targeting Brazilian financial services, retail, and eCommerce organizations since early 2024. This group specializes in manipulating payment systems and banking software to conduct fraudulent transfers and is noted for using generative AI in malware development, potentially increasing the scale and sophistication of future operations.