Slim Spider Infiltrates Brazilian Crypto Custody Systems

Brazilian financial firms are under assault from a cybercrime group dubbed Slim Spider. According to research, the group has been targeting Brazil’s financial institutions since at least March 2026. Its victims have included institutions offering cryptocurrency custody services as well as those operating the instant payments network Pix. The adversary’s operations are marked by deep expertise in both cloud infrastructure and Brazil’s financial technology environment.

How the Attack Unfolded

Slim Spider launched a multi-stage intrusion at one institution in late March. It began by executing custom Bash scripts intended to query cloud instance metadata so as to extract temporary credentials via socket connections. From there, attackers accessed the cloud credential manager, listed all stored secrets, and manipulated secret-extraction scripts through command-line tools. A key goal was to harvest credentials related to digital asset holdings.

Once those credentials were exfiltrated, the group used “cast”—a tool from the Foundry Ethereum development environment—to derive wallet addresses linked to stolen private keys. Instead of relying on third-party cryptographic libraries (which risk detection), Slim Spider embedded cryptographic signing in its Bash scripts using OpenSSL. This approach underscores a high level of operational security and understanding of cloud environments.

Blending In & Expanding Access

The threat actors did not stop at credentials. To maintain persistence and avoid detection, they infiltrated the organization’s container clusters and deployed backdoors disguised as legitimate infrastructure binaries. Additional access was gained through compromised credentials to Azure DevOps, which the attackers used to launch malicious pipelines spreading implants across managed Kubernetes clusters. One implant was labeled “spi,” likely meant to mirror Brazil’s central digital payment system, SPI (Sistema de Pagamentos Instantâneos), thereby camouflaging its true nature.

Slim Spider’s toolkit also includes several web-based control panels automating reconnaissance and fraudulent operations. These include NEXUS (for scanning APIs), Painel de Emails Entra ID (for inspecting compromised Microsoft 365 accounts), and Painel Pix (for initiating mass unauthorized Pix transfers). A command-and-control panel uncovered by researchers already showed host machines from multiple banks and fintechs in Brazil, suggesting wide breach impact. Additionally, a Go-based backdoor called MikeDor has been observed, harvesting sensitive data and tracking user activity.

Extraordinary knowledge of cloud attack surfaces allowed Slim Spider to specifically target the credentials controlling custody wallets. Access to those credentials can give attackers direct control over cryptocurrency assets, making them some of the most tempting targets for financial harm.

Slim Spider isn’t alone. Another group, Breeze Comet (also known under aliases like CL-CRI-1163 and Plump Spider), is reportedly targeting the same Brazilian financial systems. Breeze Comet is believed to focus on abusing payment infrastructure—including Pix, Boleto, and the STR system—by initiating fraudulent transactions from compromised systems. While earlier attacks by this group emerge as far back as 2024, their more recent behaviors show a shift toward infiltrating core payments infrastructure for direct financial theft.

Their activities highlight how Pix—Brazil’s instant payment system and among the most heavily used payment methods in the country—has become a prominent target across cybercrime operations. The dual threat of Slim Spider and Breeze Comet appears to reflect a pivot in strategy among cybercriminals operating in Latin America: moving from high-volume retail fraud to deep system breaches aimed at high-value assets.

Observing the techniques used by Slim Spider and Breeze Comet reveals a concerning evolution in cyber threats: adversaries are increasingly cloud savvy, stealthy, and financially focused. Organizations in Brazil—and globally—must reassess their cloud security, particularly around credential management, DevOps pipeline hygiene, infrastructure monitoring, and detection of seemingly benign binaries that might be backdoors. The cost of neglecting these areas could be irreversible.