CiberLATAMbywhalemate

Brazil: Breeze Comet hit Pix

Google and Mandiant tied Breeze Comet to hundreds of fraudulent transactions in Brazil and persistent access to financial networks.

Whalemate Labs · AI-assisted researchPublished:3 min read

Google Threat Intelligence Group and Mandiant describe Breeze Comet, also tracked as UNC5669 or Plump Spider, as an operation active since at least 2024 against Brazilian financial organizations with transactional access to Pix, STR and Boleto. According to the report, the group carried out hundreds of fraudulent transfers and erased event logs to hide the intrusion.

Google Threat Intelligence Group and Mandiant describe Breeze Comet, also tracked as UNC5669 or Plump Spider, as an operation active since at least 2024 against Brazilian financial organizations with transactional access to Pix, STR and Boleto. According to those investigations, the group carried out hundreds of fraudulent transactions by directly manipulating payment infrastructure, then erased event logs to cover up the intrusion.

How did Breeze Comet get into financial networks?

The most common initial access combined identity abuse, fraud and exploitation of vulnerable software. The campaign included password spraying against corporate accounts, WhatsApp messages impersonating IT support to push the installation of remote access tools such as AnyDesk, exploitation of vulnerable JBoss AS servers, and the use of compromised Brazilian government websites as staging points for RMM tools, infostealers and backdoors.

That pattern points to an operation that does not rely on a single entry point. Sources cited by Rootnotes.in, based on Google Threat Intelligence Group and Mandiant reporting, say the intrusion chain blends social engineering with already compromised infrastructure to help the attackers move inside corporate environments.

What tools did it use to maintain access?

Breeze Comet maintained persistence with at least four backdoor families, including LIGHTPAINT and MILDFROST. LIGHTPAINT, written in Java, installs a SoftEther VPN tunnel, while MILDFROST is a passive JAR file that implements DNS tunneling.

DarkReading added that CobaltSpin works as a network tunnel from compromised internal machines to command and control infrastructure. That design is meant to move through tightly segmented networks and the firewalls common in financial environments, which supports the idea that the goal was to reach core payment applications rather than limit itself to direct theft of customer credentials.

What do other campaigns tied to Brazil's financial sector show?

The rest of the material points to a broader ecosystem of intrusion, access brokerage and financial fraud in Brazil. Mallory attributes BraZetsu to the criminal operation Exilware and describes it as a Python backdoor used as an initial access brokerage framework against financial and corporate targets, with persistence and host profiling for sale on a black market.

Fenati adds that BraZetsu automates intrusions with AI components, infects Windows systems and lets access to machines in Brazil be sold for amounts around R$30, paid in cryptocurrency. Separately, The Hacker News reported an incident against a Brazilian financial institution in March 2026, where Slim Spider compromised cloud servers to capture crypto custody keys and access to Pix accounts, using the MikeDor backdoor to exfiltrate information and monitor user activity.

Security Affairs also reported the Coyote banking trojan as malware that steals data from more than 70 Brazilian financial apps and websites. Taken together, the available sources outline active campaigns against the country's financial sector, although they do not identify local victims in every case or spell out the full scope of each incident.

Sources

View all