'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket. A cybercrime group is infiltrating Brazilian financial systems to abuse payment infrastructure and send itself illegal transactions. "Breeze Comet," formerly known as UNC5669, goes straight to the source. It targets financial institutions: financial services, fintech, retail, point-of-sale (PoS), and e-commerce companies, plus government organizations and banks.
In other cases, they would connect their own hardware directly into retail store networks to establish initial access points. Related: Interpol's Jackal IV Disrupts West African Crime Infrastructure The Brazilian group seems to have landed on its most effective intrusion strategy midway through last year. It identified small, insufficiently secure Brazilian government websites, staged its malware on those sites, and leveraged their trusted domains in follow-on social engineering attacks against its actual targets. After the point of intrusion, Breeze Comet uses an arsenal of custom malware designed to achieve privilege escalation, lateral movement, and persistence.
Related: 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft The group's most interesting malware, perhaps, is "CobaltSpin," which weasels through strictly segmented and firewalled financial networks by establishing a network tunnel from an internal, compromised machine out to its command-and-control (C2) infrastructure. "Maybe that's a two-factor authentication (2FA), maybe that's a passkey, whatever it may be — ensuring that an API call can't trigger these transactions and there is some sort of secondary process involved." Breeze Comet can be viewed as a direct outgrowth of socioeconomic forces dating back to the 1990s, if not earlier.
Who is affected
Among them, "RealBreeze" brute-forces Lightweight Directory Access Protocol (LDAP) directory servers, "LightPaint" installs a legitimate VPN to establish persistence, and "KickPlate" impersonates Windows Update Health Tools while modifying Windows services, manipulating registry startup keys, and facilitating the installation of supplementary payloads.
The goal, ultimately, is to reach the financial applications that organizations use to make payments — in Brazil's case, systems like Pix , Boleto, and the Reserves Transfer System (STR).
So they study an organization to figure out how they could potentially get those transactions to execute without triggering their fraud and abuse systems." At that point, it's time to cash out.
In one case observed by researchers, Breeze Comet executed hundreds of fraudulent transactions within 24 to 48 hours of obtaining access to a targeted payment system, and stole an amount of Brazilian Real equivalent to tens of thousands of dollars.
Edwards advises that organizations watch out for this activity by identifying the tunnels and RMMs Breeze Comet uses to perform internal network commands.
And, he warns, "The way that they've been targeting the financial institutions — that model can be replicated across other sectors." Nate Nelson is a journalist and award-winning scriptwriter.
Why this matters
In other cases, they would connect their own hardware directly into retail store networks to establish initial access points.
Related: Interpol's Jackal IV Disrupts West African Crime Infrastructure The Brazilian group seems to have landed on its most effective intrusion strategy midway through last year.
It identified small, insufficiently secure Brazilian government websites, staged its malware on those sites, and leveraged their trusted domains in follow-on social engineering attacks against its actual targets.
After the point of intrusion, Breeze Comet uses an arsenal of custom malware designed to achieve privilege escalation, lateral movement, and persistence.
This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers.
The technical picture
Related: 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft The group's most interesting malware, perhaps, is "CobaltSpin," which weasels through strictly segmented and firewalled financial networks by establishing a network tunnel from an internal, compromised machine out to its command-and-control (C2) infrastructure.
"Maybe that's a two-factor authentication (2FA), maybe that's a passkey, whatever it may be — ensuring that an API call can't trigger these transactions and there is some sort of secondary process involved." Breeze Comet can be viewed as a direct outgrowth of socioeconomic forces dating back to the 1990s, if not earlier.
What to watch next
Watch for revised fixed-version guidance and confirmation that mitigations are holding in affected environments.
What remains unknown
The available reporting does not establish whether the issue is being actively exploited in the wild.