CyberSecurityNews

BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers


Brazilian banks and payment companies are facing a more direct form of cybercrime. BREEZE COMET, a financially motivated group formerly tracked as UNC5669, targets the systems that move money instead of individual account holders.

Its goal is to gain trusted access and submit fraudulent transfers through legitimate financial channels. The campaign has affected financial services, retail and eCommerce organizations since 2024.

Attackers have used password spraying, calls impersonating IT support, compromised public websites and rogue devices connected to retail networks. Analysts at Google Cloud identified the group’s use of custom malware alongside generative AI.

This combination helps operators search networks, test stolen credentials, move between systems and prepare data theft faster. It gives a conventional intrusion a clearer route to payment fraud.

Google Cloud said in a report shared with Cyber Security News (CSN) that the activity overlaps with operations publicly called Plump Spider and SHADOW-AETHER-064.

Researchers also warned that the infrastructure patterns may signal a broader footprint across Latin America and Africa.

BREEZE COMET Hackers Use AI-Assisted Malware

The attackers focus on organizations allowed to submit transactions through banking software, APIs and systems including Pix, STR and Boleto.

To succeed, they need access to the National Financial System Network, authenticated mTLS credentials, privileged accounts and knowledge of transfer controls.

Early intrusions used password spraying and voice phishing, with criminals posing as support staff and urging victims to install remote management tools. Later campaigns used compromised municipal websites to host lures disguised as tax or receipt documents.

The group also connected rogue hardware directly to retail networks, then moved to internal systems. The scenario reinforces hijacked finance mailbox fraud, where trusted access can enable unauthorized payment changes.

BREEZE COMET searches developer and cloud environments for pipeline credentials, API keys, cloud tokens, certificates and mTLS material. Its REALBREEZE tool attempts to guess directory credentials.

Development secrets can widen an intrusion, as recent cloud credential theft attacks have also shown. COBALTSPIN, a Rust-based tunneling tool, moves traffic through a reverse SOCKS5 proxy over WebSocket connections.

LIGHTPAINT, MILDFROST, KICKPLATE and BOATBEAM provide overlapping backdoor access. LIGHTPAINT installs a VPN, while MILDFROST can use DNS for a quieter fallback channel. KICKPLATE changes startup settings and services, and BOATBEAM hides its traffic behind a fake HTTPS server.

Researchers found evidence that large language models supported scripts for network discovery, credential validation, mass deployment, victim-specific routing and data extraction. AI did not replace criminal expertise, but it appears to have shortened the time needed to tailor tools to victims.

This means defenders may have less time between a first suspicious login and a payment attempt, especially when several compromised environments are managed by the same operator.

The final fraud stage can move quickly. In one case, BREEZE COMET used COBALTSPIN and compromised privileged accounts to access core financial applications.

Within 24 to 48 hours, it carried out two waves containing hundreds of fraudulent transactions, then cleared logs and deleted directories to conceal its activity.

Defending Payment and Cloud Environments

Organizations should block unapproved remote management tools and prevent software from running in user-writable folders. Employees need a clear way to verify unexpected support calls, while external portals should use phishing-resistant MFA and lockout controls.

Retail and branch networks need physical safeguards as well as digital ones. Deploying 802.1X network access control, disabling unused switch ports, limiting approved device addresses and securing network closets can prevent rogue devices joining internal networks.

Cloud teams should enforce least privilege for Kubernetes service accounts, block privileged containers and apply outbound network policies. They should keep secrets out of source code and environment files, as Kubernetes misconfiguration security risks demonstrate.

Finally, defenders should watch for unusual PowerShell activity, new services, startup changes, DNS tunneling, remote desktop sessions and payment API access.

They should also review certificate use, CI/CD access and unexpected proxy traffic, then isolate affected hosts while preserving logs for investigation.

Security teams should inspect suspicious traffic to public-sector domains rather than allowing it solely because the domain has a good reputation.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
SHA-2563b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceecPublished file indicator
SHA-2562214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439aPublished file indicator
SHA-256c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78aPublished file indicator
SHA-2566d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6cebPublished file indicator
SHA-256f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4fPublished file indicator
SHA-25651fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6Published file indicator
SHA-256d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66Published file indicator
SHA-256447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8Published file indicator
Domaindontpad[.]comPublic notepad service used for cloud-secret exfiltration
URLhxxps://procon[.]go[.]gov[.]br/ComprovantePDF[.]exeStaging or payload delivery URL
URLhxxps://cmgovernadorluizrocha[.]ma[.]gov[.]br/Comprovantepdf[.]exeStaging or payload delivery URL
URLhxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/ti[.]zipStaging or payload delivery URL
URLhxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/notepadd[.]exeStaging or payload delivery URL
URLhxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/tes[.]exeStaging or payload delivery URL
URLhxxps://minacu[.]go[.]gov[.]br/ComprovantePDF[.]exeStaging or payload delivery URL
URLhxxps://conseg[.]ssp[.]go[.]gov[.]br/COAF-POLICIAFEDERAL[.]exeStaging or payload delivery URL
URLhxxps://conseg[.]ssp[.]go[.]gov[.]br/ComprovanteBBpix[.]exeStaging or payload delivery URL
URLhxxps://suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/attvpn[.]zipStaging or payload delivery URL
URLhxxps://suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/1[.]exeStaging or payload delivery URL
URLhxxps://tisup[.]camaratunapolis[.]sc[.]gov[.]br/SoftEther[.]exeStaging or payload delivery URL
URLhxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/s[.]zipStaging or payload delivery URL
URLhxxp://suporte[.]ourinhos[.]sp[.]gov[.]br:443/files/s[.]exeStaging or payload delivery URL
URLhxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/a[.]exeStaging or payload delivery URL
URLhxxps://servicos[.]salto[.]sp[.]gov[.]br/j[.]jarStaging or payload delivery URL
URLhxxps://www[.]mrtb[.]gov[.]ng/apps/attvpn[.]vipStaging or payload delivery URL
URLhxxp://credeb[.]gov[.]gn/r[.]zipStaging or payload delivery URL
URLhxxps://sit[.]baer[.]gob[.]ve/r[.]exeStaging or payload delivery URL
URLhxxps://jmcov[.]gov[.]py/cxv[.]exeStaging or payload delivery URL
File nameComprovantePDF.exeMalicious lure presented as a legitimate document
File nameDnsCommandBeacon.classJava class associated with the MILDFROST DNS-tunneling backdoor

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.



Source link