Mandiant, a part of Google Threat Intelligence Group (GTIG), has been investigating a series of compromises affecting Brazilian financial services, retail, and eCommerce organizations since the beginning of 2024. GTIG tracks this activity under the name BREEZE COMET, previously known as UNC5669. This financially motivated threat actor focuses on manipulating payment systems and banking software within Brazil to execute fraudulent transfers. Their operations overlap with activities reported publicly as Plump Spider and SHADOW-AETHER-064.
BREEZE COMET's tactics have evolved to include a customized malware suite and the use of compromised, trusted websites. These websites facilitate initial access, command and control (C2), and interaction with financial software and payment APIs. The group's operational infrastructure indicates a potential intent to expand its footprint into other Latin American and African countries. There is also evidence that BREEZE COMET is utilizing generative artificial intelligence (AI) to support malware development, which could increase the scale, speed, and sophistication of their future operations.
BREEZE COMET operations specifically target organizations with permissions to conduct transactions through banking software, APIs, and payment systems such as Pix, STR (Brazilian Reserves Transfer System), and Boleto. This includes banks, payment processors, retailers, exchanges, and fintech and banking software providers. To achieve fraudulent transfers, BREEZE COMET requires access to the National Financial System Network (RSFN), mTLS credentials for authenticated transactional orders, persistent access to Active Directory or cloud environments, and an understanding of an organization’s transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Mandiant, part of Google Threat Intelligence Group, has identified BREEZE COMET (formerly UNC5669) as a financially motivated threat actor actively targeting Brazilian financial services, retail, and eCommerce organizations since early 2024. This group specializes in manipulating payment systems and banking software to conduct fraudulent transfers and is noted for using generative AI in malware development, potentially increasing the scale and sophistication of future operations.