Brazil financial sector targeted by Unit 42
Unit 42 found two active campaigns in Latin America. One targeted Brazil's financial sector with job phishing, RATs and SOCKS5 tunnels.
Unit 42 at Palo Alto Networks identified two active campaigns in Latin America, and one of them targeted Brazil's financial sector. According to the company, the operation expanded a prior pattern of attacks on vulnerable web servers by using job-themed phishing, custom RATs, tunneling tools and its own operating infrastructure.
Unit 42 at Palo Alto Networks identified two active campaigns in Latin America, and one of them targeted Brazil's financial sector. According to the company, the operation expanded a prior pattern of targeting vulnerable web servers by using job-themed phishing, custom remote access Trojans (RATs), tunneling tools, and a Go-based SOCKS5 proxy with iterative file names.
What did Unit 42 observe in the campaign tied to Brazil?
Unit 42 said the attackers used resume lures and their own operational infrastructure to sustain the activity. The campaign revived an intrusion pattern already seen against vulnerable web servers, but paired it with job-themed lures to reach environments tied to Brazil's financial sector.
The investigation also cites tunneling tools, including a Go-developed SOCKS5 proxy, along with custom RATs. That combination appears aimed at enabling remote access and movement inside compromised networks while keeping the operation under attacker control.
How does CL-CRI-1163 fit into this case?
CL-CRI-1163 was linked by third parties to the Brazilian campaign and has also been referred to as Breeze Comet, Plump Spider, and SHADOW-AETHER-064. The Hacker News described it as a cybercrime group that infiltrates Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for profit.
Google Cloud, in a threat intelligence analysis, also explicitly mapped Breeze Comet to CL-CRI-1163 and placed it as a financially motivated actor targeting segmented Brazilian financial networks. That report added that the group deploys COBALTSPIN, specialized routing malware used to move laterally and evade internal firewalls.
What does the technical analysis add about the tooling?
COBALTSPIN is documented as a reverse SOCKS5 proxy over WebSocket, designed to securely route traffic between command-and-control infrastructure and internal targets. That detail reinforces that this actor's use of SOCKS5 tunneling goes beyond the SockTz tool observed by Unit 42.
Independent specialized coverage also said that CL-CRI-1163, associated with Breeze Comet, not only uses a Go-based SOCKS5 proxy, but also relies on its own infrastructure and compromised WordPress sites to deploy multiple successive versions of the SockTz tunnel before moving to infrastructure controlled by the group. The same coverage said the cluster reuses SOCKS5 relay infrastructure shared with another Latin American cluster and uses open directories with Python scripts generated with language models.
The Hacker News placed the activity of Breeze Comet and CL-CRI-1163 in parallel with another operation, Slim Spider, against Brazilian fintechs. Although it treats them as separate groups, it emphasizes that both campaigns share a focus on critical Brazilian financial infrastructure, reflecting simultaneous pressure on that ecosystem.
Sources
- Hackers Use Claude and GPT-Powered Tools to Help ...cybersecuritynews.com· CybersecurityNews
- 브라질을 표적으로 삼는 금전적 동기의 공격자 BREEZE COMETcloud.google.com· Google Cloud
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial ...thehackernews.com· The Hacker News
- Unit 42unit42.paloaltonetworks.com· Palo Alto Networks Unit 42



