Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet (formerly UNC5669) is a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since at least September 2023, executing hundreds of fraudulent transactions through manipulated payment systems. The group employs sophisticated initial access methods including password spraying, social engineering via voice calls and WhatsApp impersonating IT support, and exploitation of vulnerable JBoss AS servers to deploy web shells. Breeze Co
Analysis
TL;DR
- Breeze Comet (formerly UNC5669) is a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since at least September 2023, executing hundreds of fraudulent transactions through manipulated payment systems.
- The group employs sophisticated initial access methods including password spraying, social engineering via voice calls and WhatsApp impersonating IT support, and exploitation of vulnerable JBoss AS servers to deploy web shells.
- Breeze Comet utilizes a custom malware suite including COBALTSPIN (Rust-based network tunneler), LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM backdoors, evolving from commercial RMM tools to malicious Kubernetes pods and cloud secret exfiltration.
- Successful attacks require four critical prerequisites: RSFN network access, mTLS credentials for Pix/STR transactions, Active Directory and cloud account access, and deep understanding of organizational transfer procedures and anti-fraud systems.
- The threat actor's infrastructure and tactics indicate potential expansion into other Latin American and African countries, with similar modus operandi already observed in Nigeria, Paraguay, Ghana, and Venezuela.
Why It Matters
This threat actor represents a significant and evolving risk to financial institutions and payment processors in Brazil and potentially beyond, demonstrating how e-crime groups are increasingly combining social engineering, custom malware development, and cloud-native attack techniques to target payment infrastructure. The sophistication of Breeze Comet's operations—particularly their use of custom backdoors, Kubernetes-based persistence, and WebSocket-based lateral movement—highlights the growing capability of financially motivated threat groups to conduct large-scale financial fraud while evading detection.
Technical Details
- Initial Access Vectors: Password spraying against financial entities, voice calls impersonating IT support to install RMM tools (AnyDesk), WhatsApp-based social engineering to deploy PowerShell reconnaissance scripts, and exploitation of vulnerable JBoss AS servers to deploy web shells for delivering Chisel and proxy utilities.
- Custom Malware Arsenal: COBALTSPIN—a Rust-based routing malware establishing reverse SOCKS5 proxy over WebSocket connections for lateral movement through boundary firewalls without built-in persistence; LIGHTPAINT (Java-based backdoor installing SoftEther VPN for automated persistence); MILDFROST (passive Java JAR backdoor using covert DNS tunnels); KICKPLATE (Nim-based backdoor impersonating Windows Update Health Tools); BOATBEAM (Golang-based backdoor running fake IIS HTTPS server on port 443).
- Reconnaissance and Lateral Movement: Use of Impacket, ADRecon, ADVipscan, and custom LDAP brute-forcing utility REALBREEZE for internal reconnaissance; unauthorized RDP sessions and SMB network file shares for lateral movement; rogue hardware devices connected directly to retail store networks.
- Persistence and Exfiltration Evolution: Shifted from dropping commercial RMM tools (2024) to deploying malicious Kubernetes pods (2025), exfiltrating cloud secrets to public notepad websites like dontpad.com, and using multiple custom backdoors for redundant access; disables Windows Defender real-time monitoring via PowerShell.
- Target Infrastructure: Organizations with access to Pix, STR, and Boleto payment systems through banking software and APIs; requires access to the National Financial System Network (RSFN), mTLS credentials for authenticated transactional payloads, multiple Active Directory and cloud accounts, and knowledge of transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.
Industry Insight
- Financial institutions and payment processors in Brazil should urgently audit their RSFN access controls, mTLS credential management, and Active Directory security, as Breeze Comet's success depends on obtaining all four critical prerequisites—implementing strict network segmentation and credential rotation policies is essential.
- The evolution toward Kubernetes-based persistence and cloud secret exfiltration indicates that organizations using containerized environments must enhance their cluster security monitoring, implement workload identity policies, and detect unauthorized pod deployments to prevent similar intrusion patterns.
- The geographic expansion of Breeze Comet's tactics to multiple African and Latin American countries suggests that regional threat intelligence sharing and coordinated defensive measures across borders should be prioritized, particularly for organizations operating in Nigeria, Paraguay, Ghana, Venezuela, and other targeted markets.
Disclaimer: The above content is generated by AI and is for reference only.