Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2626+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
NEWS

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Google tracks financially motivated group Breeze Comet manipulating Brazilian banking and payment systems like Pix, STR, and Boleto since 2024.

Dylan H.

News Desk

September 1, 2026
4 min read

What Happened

Google Threat Intelligence Group (GTIG) and Mandiant have detailed the activity of Breeze Comet, a financially motivated threat actor — previously tracked under the temporary designation UNC5669 — that has been manipulating Brazilian payment systems and banking software since 2024. Brazilian financial services, retail, and e-commerce organizations are the group's primary targets, and GTIG attributes the activity with high confidence.

The activity overlaps with clusters independently tracked by other vendors: CrowdStrike follows it as Plump Spider, and Trend Micro as SHADOW-AETHER-064. According to CrowdStrike, the group has operated out of Brazil since September 2023.


Scale and Impact

Breeze Comet monetizes intrusions by gaining unauthorized access to internal payment systems and executing fraudulent transactions directly through legitimate banking infrastructure — rather than relying on external payment fraud or card skimming. The group has carried out at least one confirmed heist worth tens of thousands of U.S. dollars, and in its most aggressive documented operation, launched two rapid waves of hundreds of unauthorized transactions within 48 hours.

The group specifically targets organizations with access to Brazil's core financial rails: Pix (Brazil's instant payment system), STR (Reserve Transfer System), Boleto (a common Brazilian payment method), the RSFN national financial network, mTLS credentials, and financial APIs. Victims span banks, fintechs, retailers, and payment processors — organizations selected specifically because they hold direct access to these payment rails, and the group demonstrates deep technical knowledge of Brazilian banking regulations and transaction processing.


Initial Access: Social Engineering and Insider Recruitment

In early compromises, Mandiant observed Breeze Comet using password spraying alongside voice phishing — calls impersonating IT support staff to convince employees to install remote monitoring and management (RMM) tools such as AnyDesk. Brazilian threat-intel firm Axur corroborates the vishing tactic and reports the group has also attempted to recruit insiders at targeted organizations directly.

Additional initial-access vectors include compromised government websites and, in some cases, physically planted rogue hardware devices inside retail networks.


Custom Tooling and Evasion

Breeze Comet's tactics have matured into a customized malware suite paired with compromised, trusted websites used for initial access, command-and-control, and direct interaction with financial software and payment APIs. Named tools observed in use include REALBREEZE, COBALTSPIN, KICKPLATE, MILDFROST, LIGHTPAINT, and BOATBEAM, covering reconnaissance, lateral movement, persistence, tunneling, and stealth.

In mid-2025, GTIG observed the group staging payloads from compromised small Brazilian government websites, including RMM tools, infostealers disguised as legitimate tax or receipt documents (such as a file named ComprovantePDF.exe), and backdoors like XWORM configured to persist through automated startup shortcut modifications.

For evasion, Mandiant observed the group clearing logs, deleting directories, and disabling Windows Defender real-time monitoring during operations. The group has also compromised municipal government websites across Brazil, Ghana, Nigeria, and Venezuela to host malicious payloads — infrastructure spread across multiple countries that helps the group's email campaigns evade domain-reputation filtering.

Notably, GTIG reports Breeze Comet has begun using generative AI to accelerate malware and script development, while expanding infrastructure and targeting into broader Latin America and Africa.


Why This Matters

Breeze Comet illustrates a maturing category of regional financial-crime actor: one that skips traditional card fraud or ATM-focused attacks entirely and instead goes straight for direct manipulation of national instant-payment infrastructure. The combination of vishing-driven RMM deployment, insider recruitment attempts, and hands-on-keyboard familiarity with systems like Pix and STR means detection has to happen at the identity and transaction-monitoring layer, not just the malware layer — by the time a custom implant is on a host, the group is often already positioned to move money. Financial institutions and payment processors in Brazil, and increasingly across Latin America and Africa as the group expands, should treat unsolicited IT-support calls requesting RMM installation as a specific, named threat pattern rather than generic social engineering.


Sources

  • The Hacker News — Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
  • Google Cloud Blog — Financially Motivated Threat Actor BREEZE COMET Targets Brazil
#Breeze Comet#UNC5669#Brazil#Financial Fraud#Threat Intelligence#Pix

Related Articles

CVE-2026-32999: Comet Backup Server Code Execution via Signing Module

A CVSS 9.0 code execution flaw in Comet Backup's backup agent signing module allows an authenticated tenant administrator to execute arbitrary code on...

5 min read

CVE-2026-3844 — Breeze Cache WordPress Plugin

A critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin allows attackers to upload arbitrary files to affected servers...

6 min read

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw

Operation Klonen: Brazilian and German authorities arrest 7 suspects behind a €30M bank fraud exploiting a third-party payment processor vulnerability at Commerzbank.

4 min read
Back to all News