Breeze Comet Hacks Brazilian Payment Systems with Sophisticated Fraud

A newly exposed Brazilian cybercrime campaign dubbed Breeze Comet—formerly known as UNC5669—has been quietly conducting large-scale fraudulent payments by breaching financial systems and payment APIs in Brazil. Active since 2024, this group has targeted banks, fintechs, payment processors, retail and e-commerce organizations to pull off operations involving “hundreds of fraudulent transactions.”

Understanding Breeze Comet’s Modus Operandi

Breeze Comet specializes in exploiting financial and payment infrastructure like Pix, STR, and Boleto—systems that facilitate instant or near-instant transactions throughout Brazil. The campaign involves entering through weak points such as JBoss AS servers compromised by web shells, or through so-called “password spraying” attacks. In many instances, attackers impersonate IT support over voice or messaging platforms to persuade victims into installing remote administration tools like AnyDesk. Once inside, they deploy reconnaissance tools and move laterally using utilities like Impacket, RDP, SMB shares, and even custom malware.

Malware, Backdoors, and Persistent Threat

After gaining access, the attackers install a variety of backdoors and custom malware tailored for persistence and evasive tactics. These include LIGHTPAINT (Java-based), MILDFROST (a passive Java JAR), KICKPLATE (Nim-based), BOATBEAM (Golang-based), and the Rust-written router malware COBALTSPIN. One notable technique: COBALTSPIN creates reverse SOCKS5 proxy tunnels over WebSockets to route traffic through compromised internal networks—circumventing firewalls without using conventional persistence methods that might raise alarms.

Persistence approaches also include compromising Kubernetes pods and stealing cloud credentials, with exfiltration via public sites like dontpad.com. On compromised hosts, Windows Defender’s real-time protections are routinely disabled to prevent detection. The group also uses compromised small government websites as C2 (command-and-control) infrastructure and to stage malware or infostealer payloads disguised as tax documents.

Executing the Heist and Covering Tracks

When sufficiently dug in, Breeze Comet carries out its fraudulent transactions using privileged and compromised credentials—often directly interfacing with banking systems and internal APIs. They may execute hundreds of fake transfers before cleaning up logs and deleting any tools or directories used—especially those that could expose API calls or malicious process history. Their efforts to avoid detection are highly systematic.

The AI Angle and Growing Threat

Threat analysts have noted that some of Breeze Comet’s tooling—scripts and malware—include verbose explanatory comments and headers that resemble LLM (large language model) outputs. These sections sometimes explicitly describe reasoning or decision-making steps, suggesting that the group may be leaning on AI to speed up development or streamline attack workflows.

Experts believe Breeze Comet may aim to expand operations beyond Brazil to other Latin American and African countries. Its evolution—jumping from opportunistic fraud to exploitation of core payment systems—marks a serious shift. Financial switches and instant payment rails are now direct targets rather than mere peripherals.

The changing tactics—especially reliance on AI, targeting payment infrastructure, stealthy lateral movement and persistent tools—show that threat actors are growing more advanced. Organizations in Brazil and neighboring regions should prioritize safeguarding mTLS credentials, tightening identity and access controls, monitoring for signs of unauthorized service installations or unusual RDP/SMB activity, and scrutinizing third-party software and cloud environments. Failure to spot attacks early could mean substantial monetary loss and systemic exposure.

What This Means Going Forward

Breeze Comet’s activity signals a tipping point: financially motivated threat groups are no longer satisfied with fraud at the edges. They are now directly crossing into core payment infrastructure—posing enormous risk not just to individual institutions, but to the entire financial ecosystem. The use of custom malware, trusted website compromises, and potentially AI-assisted development implies faster attacks and shrinking windows for defense.

It’s essential for banks, fintechs, and payment providers in Brazil and Latin America to reset their baseline assumptions. Zero trust around infrastructure access, tight control over internal tools, and real-time detection capabilities are no longer optional. What was once seen as sophisticated now looks like the new normal. Observers should watch carefully to see how regulatory bodies and industry consortia respond—or fail to respond—to this rising threat.