Brazilian payment rails face a more targeted cybercrime model
Google Threat Intelligence Group says a financially motivated actor it tracks as BREEZE COMET has compromised Brazilian financial services, retail and e-commerce organizations since 2024. The group is described as targeting banking software, payment APIs and organizations with authority to move money through systems including Pix, STR and Boleto. Mandiant also says it found evidence that large language models were used to help build operational scripts. The report points to a shift from retail banking fraud toward direct intrusions into financial infrastructure.Why BREEZE COMET matters to Brazilian finance
GTIG tracks BREEZE COMET, formerly UNC5669, as a financially motivated threat actor focused on manipulating payment systems and banking software in Brazil. The targets described by Mandiant include banks, payment processors, retailers, exchanges, fintech companies and banking software providers - organizations that may have access to transaction systems rather than only customer-facing accounts.That distinction changes the risk profile. A compromise inside a business with permission to initiate transfers can give attackers a route toward authenticated payment activity, especially if they also obtain privileged accounts, certificates or cloud secrets. Mandiant says the actor needs knowledge of transfer procedures, network controls, fintech integrations and anti-fraud systems, which suggests a more patient and environment-specific form of financial cybercrime.
Initial access mixed social engineering, websites and hardware
Mandiant says BREEZE COMET has used several entry methods rather than relying on one repeatable intrusion path. Earlier activity included password spraying and voice calls impersonating IT support to persuade users to install remote management tools. Axur, cited by GTIG, corroborated voice phishing and suggested attempts to recruit insiders at targeted organizations.In mid-2025, GTIG observed the group using compromised Brazilian small government websites to stage malicious tools and support social engineering. The report says trusted infrastructure helped the actor avoid some reputation-based filtering, a useful reminder that domain trust alone is a weak control for financial networks. GTIG also observed similar municipal-domain activity in Nigeria, Paraguay, Ghana and Venezuela, which it says may indicate an expanding infrastructure footprint.
Custom tooling supported movement toward payment systems
The report describes BREEZE COMET as using custom malware alongside public reconnaissance tools to move through compromised environments. Mandiant names tools including REALBREEZE, COBALTSPIN, LIGHTPAINT, MILDFROST, KICKPLATE and BOATBEAM, but the central point for defenders is not the branding. The actor appears to maintain redundant access paths, search for credentials and certificates, and use tooling designed to reach segmented financial infrastructure.Mandiant says BREEZE COMET has targeted Active Directory, cloud environments and development pipelines to steal credentials, API keys and privileged cloud tokens. The group also searched for material needed to authenticate against core banking systems. For financial firms, that links software development security, secrets management and payment-system segmentation into one control problem rather than separate IT projects.
Fraud followed access to core applications
Forensic evidence analyzed by Mandiant indicates that BREEZE COMET used custom routing malware and compromised privileged accounts to access core financial applications. Based on client reporting and third-party forensic analysis cited in the report, the actor executed two waves of hundreds of fraudulent transactions within 24 to 48 hours after establishing that access.Mandiant says the group later cleared logs across compromised hosts and deleted directories created during the intrusion. Since 2024, the report says BREEZE COMET has increased the complexity and effectiveness of operations manipulating Brazilian financial systems and software, and has executed at least one heist of tens of thousands of U.S. dollars in assets. The figures are not presented as market-wide losses, but they show that the campaign has moved beyond theoretical capability.
AI use points to faster attacker development cycles
Mandiant says it identified evidence that BREEZE COMET used large language models to accelerate custom scripts for reconnaissance, credential validation, mass deployment, victim-specific pivoting and data extraction. The report says recovered scripts were functional and highly customized while showing features such as verbose explanatory comments and standardized headers.That does not mean AI created the operation by itself. The campaign still depended on access, infrastructure, credential theft and knowledge of financial workflows. The practical implication is narrower but serious: if LLMs reduce development time for routine attacker tooling, defenders may have less time between initial access, internal discovery and movement toward payment applications.
Defensive priorities for financial and retail networks
GTIG’s mitigation guidance focuses on reducing easy footholds and limiting movement once an attacker is inside. The recommendations include controlling unapproved remote management tools, training users against IT-support impersonation, hardening branch network access, restricting administrative utilities and requiring phishing-resistant multifactor authentication on external portals.The report also emphasizes monitoring outbound traffic, segmenting internal access between workstations and servers, strengthening Kubernetes and cloud workload controls, and moving secrets out of plaintext code. For organizations connected to payment rails, those measures are not generic hygiene. They directly address the paths Mandiant says BREEZE COMET used to turn enterprise compromise into payment-system fraud.
Conclusion
BREEZE COMET shows how financially motivated intrusion groups can combine social engineering, compromised trusted websites, cloud credential theft, custom malware and AI-assisted scripting against payment infrastructure. GTIG’s findings are especially relevant to Brazilian financial services and retail organizations, but the reported use of municipal infrastructure outside Brazil makes the campaign worth watching beyond one market.The defensive lesson is concrete: payment authority, secrets, cloud access and branch networks must be treated as parts of the same attack surface. Faster attacker tooling makes detection speed and segmentation more valuable, not less.
Sources
Editorial Team - CoinBotLab