AI Security AI安全 5h ago Updated 2h ago 更新于 2小时前 38

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems Breeze Comet通过巴西支付系统执行数百笔欺诈交易

Breeze Comet (formerly UNC5669) is a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since at least September 2023, executing hundreds of fraudulent transactions through manipulated payment systems. The group employs sophisticated initial access methods including password spraying, social engineering via voice calls and WhatsApp impersonating IT support, and exploitation of vulnerable JBoss AS servers to deploy web shells. Breeze Co Breeze Comet(前UNC5669)自2024年起专门针对巴西金融服务、零售和电商组织,通过操控支付系统和银行软件进行欺诈转账,已实施至少一起数万美元规模的资产盗窃 攻击者采用密码喷洒、语音钓鱼(伪装IT支持人员诱导安装AnyDesk等RMM工具)、WhatsApp社交工程及JBoss AS漏洞利用等多种初始访问手段 该组织开发了完整的定制恶意软件套件,包括COBALTSPIN(Rust网络隧道)、LIGHTPAINT、MILDFROST、KICKPLATE、BOATBEAM等多种后门,并持续演进持久化技术(从RMM工具到恶意Kubernetes Pod) 成功攻击需满足四个关键条件:

55
Hot 热度
60
Quality 质量
50
Impact 影响力

Analysis 深度分析

TL;DR

  • Breeze Comet (formerly UNC5669) is a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since at least September 2023, executing hundreds of fraudulent transactions through manipulated payment systems.
  • The group employs sophisticated initial access methods including password spraying, social engineering via voice calls and WhatsApp impersonating IT support, and exploitation of vulnerable JBoss AS servers to deploy web shells.
  • Breeze Comet utilizes a custom malware suite including COBALTSPIN (Rust-based network tunneler), LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM backdoors, evolving from commercial RMM tools to malicious Kubernetes pods and cloud secret exfiltration.
  • Successful attacks require four critical prerequisites: RSFN network access, mTLS credentials for Pix/STR transactions, Active Directory and cloud account access, and deep understanding of organizational transfer procedures and anti-fraud systems.
  • The threat actor's infrastructure and tactics indicate potential expansion into other Latin American and African countries, with similar modus operandi already observed in Nigeria, Paraguay, Ghana, and Venezuela.

Why It Matters

This threat actor represents a significant and evolving risk to financial institutions and payment processors in Brazil and potentially beyond, demonstrating how e-crime groups are increasingly combining social engineering, custom malware development, and cloud-native attack techniques to target payment infrastructure. The sophistication of Breeze Comet's operations—particularly their use of custom backdoors, Kubernetes-based persistence, and WebSocket-based lateral movement—highlights the growing capability of financially motivated threat groups to conduct large-scale financial fraud while evading detection.

Technical Details

  • Initial Access Vectors: Password spraying against financial entities, voice calls impersonating IT support to install RMM tools (AnyDesk), WhatsApp-based social engineering to deploy PowerShell reconnaissance scripts, and exploitation of vulnerable JBoss AS servers to deploy web shells for delivering Chisel and proxy utilities.
  • Custom Malware Arsenal: COBALTSPIN—a Rust-based routing malware establishing reverse SOCKS5 proxy over WebSocket connections for lateral movement through boundary firewalls without built-in persistence; LIGHTPAINT (Java-based backdoor installing SoftEther VPN for automated persistence); MILDFROST (passive Java JAR backdoor using covert DNS tunnels); KICKPLATE (Nim-based backdoor impersonating Windows Update Health Tools); BOATBEAM (Golang-based backdoor running fake IIS HTTPS server on port 443).
  • Reconnaissance and Lateral Movement: Use of Impacket, ADRecon, ADVipscan, and custom LDAP brute-forcing utility REALBREEZE for internal reconnaissance; unauthorized RDP sessions and SMB network file shares for lateral movement; rogue hardware devices connected directly to retail store networks.
  • Persistence and Exfiltration Evolution: Shifted from dropping commercial RMM tools (2024) to deploying malicious Kubernetes pods (2025), exfiltrating cloud secrets to public notepad websites like dontpad.com, and using multiple custom backdoors for redundant access; disables Windows Defender real-time monitoring via PowerShell.
  • Target Infrastructure: Organizations with access to Pix, STR, and Boleto payment systems through banking software and APIs; requires access to the National Financial System Network (RSFN), mTLS credentials for authenticated transactional payloads, multiple Active Directory and cloud accounts, and knowledge of transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.

Industry Insight

  • Financial institutions and payment processors in Brazil should urgently audit their RSFN access controls, mTLS credential management, and Active Directory security, as Breeze Comet's success depends on obtaining all four critical prerequisites—implementing strict network segmentation and credential rotation policies is essential.
  • The evolution toward Kubernetes-based persistence and cloud secret exfiltration indicates that organizations using containerized environments must enhance their cluster security monitoring, implement workload identity policies, and detect unauthorized pod deployments to prevent similar intrusion patterns.
  • The geographic expansion of Breeze Comet's tactics to multiple African and Latin American countries suggests that regional threat intelligence sharing and coordinated defensive measures across borders should be prioritized, particularly for organizations operating in Nigeria, Paraguay, Ghana, Venezuela, and other targeted markets.

TL;DR

  • Breeze Comet(前UNC5669)自2024年起专门针对巴西金融服务、零售和电商组织,通过操控支付系统和银行软件进行欺诈转账,已实施至少一起数万美元规模的资产盗窃
  • 攻击者采用密码喷洒、语音钓鱼(伪装IT支持人员诱导安装AnyDesk等RMM工具)、WhatsApp社交工程及JBoss AS漏洞利用等多种初始访问手段
  • 该组织开发了完整的定制恶意软件套件,包括COBALTSPIN(Rust网络隧道)、LIGHTPAINT、MILDFROST、KICKPLATE、BOATBEAM等多种后门,并持续演进持久化技术(从RMM工具到恶意Kubernetes Pod)
  • 成功攻击需满足四个关键条件:访问国家金融系统网络(RSFN)、获取mTLS证书、控制多个AD和云账户、深入了解目标转账流程和反欺诈系统
  • 攻击模式已从巴西扩展至尼日利亚、巴拉圭、加纳和委内瑞拉,显示向拉美和非洲其他地区扩张的意图

为什么值得看

本文详细披露了针对巴西金融支付系统的专业化网络犯罪团伙的完整攻击链和技术细节,对金融机构、支付服务商和网络安全从业者具有重要的威胁情报价值。攻击者展现的技术演进能力(从传统RMM到Kubernetes恶意Pod、定制后门套件)反映了现代金融网络犯罪的复杂化趋势。

技术解析

  • 初始访问技术:采用密码喷洒和语音钓鱼(伪装IT支持团队),通过WhatsApp对话诱导受害者安装AnyDesk等RMM工具或执行PowerShell侦察脚本; alternatively利用JBoss AS漏洞部署web shell,进而投放Chisel等代理工具
  • 横向移动与持久化:使用Impacket、ADRecon、ADVipscan及自定义LDAP暴力破解工具REALBREEZE进行内部侦察和权限提升;通过未授权RDP会话和SMB文件共享横向移动;部署COBALTSPIN(基于Rust的网络隧道器)建立WebSocket反向SOCKS5代理实现持久化访问
  • 定制后门套件:LIGHTPAINT(Java后门,安装SoftEther VPN实现自动化持久化)、MILDFROST(被动Java JAR后门,建立隐蔽DNS隧道)、KICKPLATE(Nim后门,伪装Windows Update Health Tools)、BOATBEAM(Golang后门,在443端口启动伪造IIS HTTPS服务器)
  • 云与容器攻击:持久化机制从2024年的商业RMM工具演变为部署恶意Kubernetes Pod,通过dontpad.com等公开图钉网站外泄云密钥;使用PowerShell禁用Windows Defender实时监测
  • 最终攻击阶段:利用COBALTSPIN和被盗特权账户访问核心金融应用,通过Pix、STR、Boleto等支付系统执行数百笔欺诈交易,完成后清除事件日志和创建的所有目录以消除取证痕迹

行业启示

  • 金融机构和支付服务商需加强对员工的社会工程学防范意识培训,特别是针对语音钓鱼和IT支持伪装的攻击手法,同时严格管控RMM工具的部署和使用权限
  • 建议部署针对新型网络隧道工具(如COBALTSPIN)和定制后门的检测能力,加强对Kubernetes集群、云环境密钥和mTLS证书的安全监控,建立对巴西支付系统(Pix/STR/Boleto)异常交易的实时风控机制
  • 关注该威胁组织向拉美和非洲地区扩张的趋势,相关地区的金融机构应加强跨境威胁情报共享,并针对RSFN网络访问、特权账户管理和反欺诈系统进行安全加固

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究