Financially Motivated Actor BREEZE COMET Targets Brazil with Sophisticated Financial Fraud
Mandiant has identified BREEZE COMET, a financially motivated threat actor targeting Brazil's financial sector with custom malware and AI-assisted development to manipulate payment systems for fraudulent transfers.

Mandiant Threat Intelligence has uncovered a sophisticated financially motivated threat actor, tracked as BREEZE COMET, that has been actively targeting organizations within Brazil's financial services sector since 2024. This group, previously known as UNC5669, specializes in manipulating payment systems and banking software to execute fraudulent transfers, impacting banks, payment processors, retailers, and fintech providers. Their operations have been observed to overlap with previously reported activities, including those attributed to Plump Spider and SHADOW-AETHER-064.
BREEZE COMET's tactics have evolved significantly, now incorporating a customized malware suite and leveraging compromised, trusted websites for initial access, command and control (C2), and interaction with financial software APIs. The group's infrastructure and operational scope suggest potential expansion into other Latin American and African countries. Notably, evidence indicates BREEZE COMET is employing generative artificial intelligence (AI) to aid in malware development, a move that could dramatically increase the scale, speed, and sophistication of their future attacks.
To achieve their objective of fraudulent transfers, BREEZE COMET requires specific access and knowledge. This includes maintaining access to Brazil's National Financial System Network (RSFN) through an authorized entity, acquiring multi-factor TLS (mTLS) credentials for authenticated transactional orders to systems like Pix and STR, and securing persistent access to multiple Active Directory and cloud environments within targeted organizations. Furthermore, the group demonstrates a deep understanding of their victims' transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.
BREEZE COMET employs a multi-pronged approach for initial compromise. Early attacks involved password spraying and social engineering tactics, such as voice phishing impersonating IT support to trick users into installing Remote Monitoring and Management (RMM) tools like AnyDesk. More recently, the group has utilized compromised Brazilian government websites to stage RMM tools, infostealers disguised as legitimate documents, and backdoors like XWORM. These compromised sites also serve as C2 endpoints, allowing BREEZE COMET to evade detection by reputation-based filters. The group has also been observed replicating this tactic with municipal domains in Nigeria, Paraguay, Ghana, and Venezuela.
Further evolving their methods, BREEZE COMET has been observed physically connecting rogue hardware devices directly into retail store networks to establish initial footholds. From these points, they move laterally to internal systems, downloading tools like Netcat and custom scripts to deploy post-exploitation frameworks. Trend Micro has also reported the group exploiting vulnerabilities in JBoss AS servers for initial access, showcasing a diverse and adaptive attack vector.
Once inside, BREEZE COMET escalates privileges and conducts internal reconnaissance using a mix of publicly available utilities like Impacket and ADRecon, alongside custom malware. They specifically target development and cloud environments, mining CI/CD pipelines for hard-coded credentials, API keys, and cloud access tokens. The group also deploys a custom LDAP brute-forcing utility called REALBREEZE and uses custom scripts to search for mTLS credentials and administrative certificates necessary for authenticating against core banking systems, looking for terms related to payment processing.
For lateral movement, BREEZE COMET abuses standard network protocols, utilizing hijacked service accounts to initiate unauthorized Remote Desktop Protocol (RDP) sessions and execute commands. Their ability to blend in with legitimate network traffic and exploit internal configurations allows them to move stealthily across compromised networks, setting the stage for their ultimate goal of financial fraud.