Hackers Use AI Malware to Break Into Brazilian Banks and Make Fraudulent Transfers

Brazilian financial organizations are facing a growing threat from a cybercrime group tracked as BREEZE COMET. Since 2024, Mandiant has investigated attacks against financial services, retail, and eCommerce companies in Brazil.

The group is financially motivated and focuses on breaking into systems that can process payments. BREEZE COMET, previously known as UNC5669, is linked to activity reported as Plump Spider and SHADOW-AETHER-064.

Its goal is not ordinary banking fraud against individual customers. Instead, it attempts to compromise organizations that have direct access to banking software, payment APIs, and Brazil’s payment infrastructure.

The attackers target banks, payment processors, fintech firms, exchanges, retailers, and banking-software providers. They seek access to systems connected to Pix, STR, Boleto, and other transaction platforms.

If successful, they can use stolen credentials and privileged accounts to submit fraudulent transfers in the name of a legitimate organization.

The group needs several things to complete its fraud operations: access to Brazil’s National Financial System Network, valid mTLS certificates, persistent access to Active Directory or cloud accounts, and knowledge of the victim’s payment processes.

This makes the attacks more complex than common phishing campaigns, but potentially far more damaging.

AI Malware Targets Brazil

BREEZE COMET has used password spraying, voice phishing, malicious remote-management tools, and rogue hardware devices to gain initial access.

In several cases, attackers pretended to be IT support staff and convinced victims to install tools such as AnyDesk.

The group also abused compromised Brazilian government websites to host malware disguised as tax documents or payment receipts. These trusted domains helped the attackers bypass reputation-based security filters.

Researchers found similar malicious infrastructure linked to government domains in Nigeria, Paraguay, Ghana, and Venezuela, suggesting that the group may expand beyond Brazil.

After entering a network, BREEZE COMET uses both public tools and custom malware to map systems, steal credentials, and move between devices.

It searches development and cloud environments for API keys, CI/CD credentials, cloud tokens, administrative certificates, and mTLS credentials used to approve financial transactions.

Its custom toolkit includes REALBREEZE, an LDAP brute-force tool; COBALTSPIN, a Rust-based network tunneler; LIGHTPAINT, a Java backdoor that installs persistent VPN access; MILDFROST, a DNS-tunneling backdoor; KICKPLATE, a Nim malware family that imitates Windows Update tools; and BOATBEAM, a Golang backdoor that hides command-and-control traffic behind a fake IIS web server.

Researchers also found evidence that the group uses generative AI and large language models to create customized scripts.

These scripts help automate network scanning, credential checks, malware deployment, victim-specific routing, and data collection.

AI use may allow attackers to develop tools faster and run attacks across several victim environments at the same time, cloud google said.

Indicators of Compromise

SHA-256 HashMalware / Tool
3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceecCOBALTSPIN
2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439aREALBREEZE

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories