The record
Written from the 1 report below. Nothing here is unsourced.
- A financially motivated hacking group called Breeze Comet, formerly tracked as UNC5669, is compromising Brazilian payment and financial systems to carry out fraudulent transactions.
- The group targets banks, payment processors, retailers, exchanges, and fintech companies that have permission to transact through systems such as Pix, STR, and Boleto, and has stolen assets worth tens of thousands of U.S. dollars in at least one heist.
- Breeze Comet gets into its targets' networks by guessing weak passwords and by posing as IT support staff over phone calls or WhatsApp to trick employees into installing remote-access tools.
- Google researchers report the group uses a custom toolkit, including a Rust-based tunneler called COBALTSPIN, to reach core financial applications, execute hundreds of fraudulent transfers, and then erase logs to hide its tracks.
- The group's infrastructure suggests plans to expand into other countries in Latin America and Africa, meaning banks and payment firms beyond Brazil face growing risk.
What to watch next
- Signs of Breeze Comet activity expanding into other Latin American and African countries, as its infrastructure hints.
- Whether Brazil's banks and payment systems add new defenses against the group's tactic of posing as IT support to install remote-access tools.
- Evolution of the group's persistence methods, which have already shifted from commercial remote tools in 2024 to malicious Kubernetes pods in 2025.
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Google Threat Intelligence Group
2 quotes · 1 outlet
“Breeze Comet tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command-and-control (C2), and to interact with financial software and payment APIs”
In the article
…software, APIs, and payment systems such as Pix, STR, and Boleto. This covers a wide range of entities like banks, payment processors, retailers, and exchanges, not to mention fintech and banking software providers. " Breeze Comet tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command-and-control (C2), and to interact with financial software and payment APIs ," Google said. "Breeze Comet's operational infrastructure may also indicate intent to expand their infrastructure footprint to other countries in Latin America and Africa." To achieve its goals, however, it must meet…
“By establishing a reverse SOCKS5 proxy over a WebSocket connection, COBALTSPIN routes network traffic securely back and forth between the C2 and internal targets, enabling lateral movement directly through boundary firewalls without requiring built-in persistence mechanisms that might trigger detection”
In the article
…This step also involves the deployment of COBALTSPIN, a Rust-based routing malware that operates as a network tunneler to communicate with and maintain persistent network access to financial API infrastructure. " By establishing a reverse SOCKS5 proxy over a WebSocket connection, COBALTSPIN routes network traffic securely back and forth between the C2 and internal targets, enabling lateral movement directly through boundary firewalls without requiring built-in persistence mechanisms that might trigger detection ," Google said. Breeze Comet's persistence mechanisms have evolved from dropping commercial RMM tools in 2024 to deploying malicious Kubernetes pods a year later and stealing cloud secrets by exfiltrating them to…
Coverage1
All filed from India
Named Brazil · Nigeria · Paraguay · Ghana · Venezuela · Axur · Breeze Comet · CrowdStrike · Google Threat Intelligence Group · Mandiant · Palo Alto Networks Unit 42 · Trend Micro
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
