Slim Spider Emerges Targeting Brazilian Financial Institutions for Crypto Assets
A new financially motivated threat actor, dubbed Slim Spider, is actively targeting Brazilian financial institutions, demonstrating advanced knowledge of local payment systems and cloud infrastructure to steal cryptocurrency custody secrets.

A previously undocumented financially motivated threat actor, identified by cybersecurity firm CrowdStrike as Slim Spider, has been actively targeting Brazilian financial institutions since at least March 2026. This Brazil-based group exhibits a sophisticated understanding of the local financial ecosystem, including the widely used instant payment service Pix, digital asset platforms, and the cloud environments utilized by financial entities.
The group's primary objective appears to be the theft of cryptocurrency custody secrets, indicating a strategic focus on high-value digital assets. In a notable incident observed in late March 2026, Slim Spider orchestrated a multi-stage intrusion at a Brazilian financial institution, specifically targeting its cryptocurrency assets and instant payment accounts.
Slim Spider employs advanced techniques to achieve its goals. The threat actor has developed custom Bash scripts designed to query cloud instance metadata and exfiltrate temporary cloud credentials over socket connections. Upon gaining access to an organization's cloud environment, the group enumerates all available secrets within the cloud credential manager. They then leverage the 'sed' command to clone and modify existing secret-extracting scripts, with a particular emphasis on credentials linked to digital financial assets.
Demonstrating a high level of operational security awareness, Slim Spider avoids relying on third-party libraries that could trigger detection. Instead, they implement cloud-native cryptographic signing directly via OpenSSL within their Bash scripts. Following the exfiltration of digital asset custody secrets, the group utilizes 'cast,' a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key. This meticulous approach highlights their deep understanding of cloud environments and cryptocurrency operations.
Further complicating detection, Slim Spider establishes access to nodes within cloud container service clusters and deploys backdoors that mimic legitimate infrastructure-related binaries. This allows them to blend in with normal network traffic and evade security monitoring. The actor has also been observed pivoting to Azure DevOps, likely using compromised credentials, to execute malicious pipelines that deploy additional implants across managed Kubernetes clusters. One such implant was named 'spi,' a deliberate attempt to impersonate the Sistema de Pagamentos Instantâneos (SPI), the central infrastructure for Pix payments.
To streamline their operations, Slim Spider utilizes a suite of custom web-based panels. These include 'NEXUS // Scanner,' an API endpoint-scanning panel that categorizes and ranks endpoints; 'Painel de Emails Entra ID,' an email reconnaissance panel for searching compromised Microsoft 365 mailboxes; and 'Painel Pix,' a panel designed for executing bulk unauthorized Pix transfers from compromised accounts. CrowdStrike also identified an exposed command-and-control (C2) panel linked to the threat actor, revealing compromised hosts from multiple Brazilian banks and fintech organizations.
Another key tool in Slim Spider's arsenal is 'MikeDor,' a Go-based backdoor capable of harvesting sensitive information and monitoring user activities. The group's proficiency in exploiting the cloud attack surface allows them to target credentials directly linked to an organization's valuable digital currency assets, including those controlling cryptocurrency wallets. This capability poses a significant risk of devastating financial loss for victim organizations.
The emergence of Slim Spider coincides with reports of another financially motivated group, Breeze Comet, also targeting Brazil's financial sector. The parallel targeting of critical infrastructure like Pix by distinct threat actors underscores the lucrative nature of Brazil's payment systems for cybercriminals. This trend signifies a broader shift in the Latin American cybercrime landscape, moving from opportunistic retail fraud to direct intrusions into core financial infrastructure.