What Happened
Google Threat Intelligence Group (GTIG) and Mandiant have detailed the activity of Breeze Comet, a financially motivated threat actor — previously tracked under the temporary designation UNC5669 — that has been manipulating Brazilian payment systems and banking software since 2024. Brazilian financial services, retail, and e-commerce organizations are the group's primary targets, and GTIG attributes the activity with high confidence.
The activity overlaps with clusters independently tracked by other vendors: CrowdStrike follows it as Plump Spider, and Trend Micro as SHADOW-AETHER-064. According to CrowdStrike, the group has operated out of Brazil since September 2023.
Scale and Impact
Breeze Comet monetizes intrusions by gaining unauthorized access to internal payment systems and executing fraudulent transactions directly through legitimate banking infrastructure — rather than relying on external payment fraud or card skimming. The group has carried out at least one confirmed heist worth tens of thousands of U.S. dollars, and in its most aggressive documented operation, launched two rapid waves of hundreds of unauthorized transactions within 48 hours.
The group specifically targets organizations with access to Brazil's core financial rails: Pix (Brazil's instant payment system), STR (Reserve Transfer System), Boleto (a common Brazilian payment method), the RSFN national financial network, mTLS credentials, and financial APIs. Victims span banks, fintechs, retailers, and payment processors — organizations selected specifically because they hold direct access to these payment rails, and the group demonstrates deep technical knowledge of Brazilian banking regulations and transaction processing.
Initial Access: Social Engineering and Insider Recruitment
In early compromises, Mandiant observed Breeze Comet using password spraying alongside voice phishing — calls impersonating IT support staff to convince employees to install remote monitoring and management (RMM) tools such as AnyDesk. Brazilian threat-intel firm Axur corroborates the vishing tactic and reports the group has also attempted to recruit insiders at targeted organizations directly.
Additional initial-access vectors include compromised government websites and, in some cases, physically planted rogue hardware devices inside retail networks.
Custom Tooling and Evasion
Breeze Comet's tactics have matured into a customized malware suite paired with compromised, trusted websites used for initial access, command-and-control, and direct interaction with financial software and payment APIs. Named tools observed in use include REALBREEZE, COBALTSPIN, KICKPLATE, MILDFROST, LIGHTPAINT, and BOATBEAM, covering reconnaissance, lateral movement, persistence, tunneling, and stealth.
In mid-2025, GTIG observed the group staging payloads from compromised small Brazilian government websites, including RMM tools, infostealers disguised as legitimate tax or receipt documents (such as a file named ComprovantePDF.exe), and backdoors like XWORM configured to persist through automated startup shortcut modifications.
For evasion, Mandiant observed the group clearing logs, deleting directories, and disabling Windows Defender real-time monitoring during operations. The group has also compromised municipal government websites across Brazil, Ghana, Nigeria, and Venezuela to host malicious payloads — infrastructure spread across multiple countries that helps the group's email campaigns evade domain-reputation filtering.
Notably, GTIG reports Breeze Comet has begun using generative AI to accelerate malware and script development, while expanding infrastructure and targeting into broader Latin America and Africa.
Why This Matters
Breeze Comet illustrates a maturing category of regional financial-crime actor: one that skips traditional card fraud or ATM-focused attacks entirely and instead goes straight for direct manipulation of national instant-payment infrastructure. The combination of vishing-driven RMM deployment, insider recruitment attempts, and hands-on-keyboard familiarity with systems like Pix and STR means detection has to happen at the identity and transaction-monitoring layer, not just the malware layer — by the time a custom implant is on a host, the group is often already positioned to move money. Financial institutions and payment processors in Brazil, and increasingly across Latin America and Africa as the group expands, should treat unsolicited IT-support calls requesting RMM installation as a specific, named threat pattern rather than generic social engineering.