← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Mandiant Details BREEZE COMET Threat Actor Targeting Brazilian Financial Services

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • BREEZE COMET targets Brazilian financial services, retail, and eCommerce.
  • The group manipulates payment systems like Pix, STR, and Boleto for fraudulent transfers.
  • BREEZE COMET uses customized malware and compromised websites for access and control.
  • Evidence suggests BREEZE COMET uses generative AI for malware development.

Threat Actor Overview

Mandiant, a part of Google Threat Intelligence Group (GTIG), has been investigating a series of compromises affecting Brazilian financial services, retail, and eCommerce organizations since the beginning of 2024. GTIG tracks this activity under the name BREEZE COMET, previously known as UNC5669. This financially motivated threat actor focuses on manipulating payment systems and banking software within Brazil to execute fraudulent transfers. Their operations overlap with activities reported publicly as Plump Spider and SHADOW-AETHER-064.

Tactics and Tools

BREEZE COMET's tactics have evolved to include a customized malware suite and the use of compromised, trusted websites. These websites facilitate initial access, command and control (C2), and interaction with financial software and payment APIs. The group's operational infrastructure indicates a potential intent to expand its footprint into other Latin American and African countries. There is also evidence that BREEZE COMET is utilizing generative artificial intelligence (AI) to support malware development, which could increase the scale, speed, and sophistication of their future operations.

Targeted Systems and Objectives

BREEZE COMET operations specifically target organizations with permissions to conduct transactions through banking software, APIs, and payment systems such as Pix, STR (Brazilian Reserves Transfer System), and Boleto. This includes banks, payment processors, retailers, exchanges, and fintech and banking software providers. To achieve fraudulent transfers, BREEZE COMET requires access to the National Financial System Network (RSFN), mTLS credentials for authenticated transactional orders, persistent access to Active Directory or cloud environments, and an understanding of an organization’s transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 31

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Mandiant, part of Google Threat Intelligence Group, has identified BREEZE COMET (formerly UNC5669) as a financially motivated threat actor actively targeting Brazilian financial services, retail, and eCommerce organizations since early 2024. This group specializes in manipulating payment systems and banking software to conduct fraudulent transfers and is noted for using generative AI in malware development, potentially increasing the scale and sophistication of future operations.