Google Cloud Blog
Follow
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Mandiant is tracking a financially motivated threat actor named BREEZE COMET, formerly known as UNC5669, which has been actively compromising Brazilian financial organizations since 2024. This group specializes in manipulating payment systems and banking software to conduct fraudulent transfers. BREEZE COMET employs a customized malware suite and utilizes compromised trusted websites for initial access and command and control. Their operations have expanded to include leveraging generative AI for malware development, potentially increasing their operational sophistication. The group targets entities with access to the National Financial System Network and requires mTLS credentials for authenticated fraudulent transactions. BREEZE COMET uses various methods for initial compromise, including voice phishing and exploiting compromised government websites. They also gain footholds by connecting rogue hardware devices directly into retail networks. To escalate privileges, they utilize reconnaissance tools and custom malware, specifically targeting cloud and development environments for credentials and API keys. BREEZE COMET moves laterally through networks using hijacked service accounts and specialized routing malware like COBALTSPIN. They maintain persistence through custom backdoors such as LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, often disabling endpoint defenses like Windows Defender. After compromising financial applications, BREEZE COMET executes mass fraudulent transactions and then clears event logs to cover their tracks. Their evolving tactics represent a significant shift in Latin American cybercrime, moving from retail fraud to direct intrusions into core financial infrastructure. BREEZE COMET's use of AI demonstrates its impact on enhancing threat actor capabilities, speed, and scale.