BREEZE COMET Turns Brazil’s Instant Payment Rails into a Cash-Out Channel
A financially motivated Brazilian eCrime group reaches core payment systems to execute fraudulent transfers across the National Financial System Network.
First Seen: September 2023
Targeted Regions: Brazil, Argentina, Bolivia, Chile, Colombia, Ecuador, French Guiana, Guyana, Peru, Suriname, Uruguay, United States, Mexico, Canada, Guatemala, Haiti, Cuba, Dominican Republic, Honduras, El Salvador, Nicaragua, Costa Rica, Panama, Jamaica, Puerto Rico, Trinidad and Tobago, Belize, Guadeloupe, Bahamas, Martinique, Barbados, Saint Lucia, Grenada, United States Virgin Islands, Antigua and Barbuda, Dominica, Bermuda, Greenland, Saint Kitts and Nevis, Saint Maarten, Anguilla, Nigeria, Paraguay, Venezuela, Ethiopia, Egypt, DR Congo, Tanzania, South Africa, Kenya, Sudan, Uganda, Algeria, Angola, Morocco, Mozambique, Ghana, Madagascar, Cameroon, Niger, Mali, Burkina Faso, Malawi, Zambia, Chad, Senegal, Zimbabwe, Guinea, Benin, Rwanda, Burundi, Tunisia, Togo, Sierra Leone, Libya, Liberia, Central African Republic, Mauritania, Namibia, Gabon, Botswana, Lesotho, Guinea-Bissau, Equatorial Guinea, Mauritius, Djibouti, Comoros, Seychelles.
Targeted Platforms: Windows, Linux, Active Directory, Cloud environments, Kubernetes, CI/CD pipelines, Java Virtual Machine (JVM) process space.
Targeted Industries: Financial Services, Fintech, Banking Software Providers, Payment Processors, Banks, Retail, Point-Of-Sale, E-Commerce, Exchanges, Government.
Threat Actor: BREEZE COMET (aka UNC5669, PLUMP SPIDER, SHADOW-AETHER-064, CL-CRI-1163)
Malware: COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, LIGHTPAINT, KICKPLATE, XWORM
Actor Details
Actor Group
| Name | Origin | Motive | Target Industries |
|---|---|---|---|
| BREEZE COMET (aka UNC5669, PLUMP SPIDER, SHADOW-AETHER-064, CL-CRI-1163) | Brazil | Financial Gain | Financial Services, Fintech, Banking Software Providers, Payment Processors, Banks, Retail, Point-Of-Sale, Ecommerce, Exchanges, Government |
Recommendations
Apply Windows WDAC, macOS Gatekeeper or MDM, and Linux fapolicyd to block execution from user-writable directories including %APPDATA%, ~/Downloads, /tmp, and /var/tmp. Mount /tmp and /home with the noexec flag on Linux hosts.
Deploy 802.1X Network Access Control across physical Ethernet switch ports at branch and retail locations so unauthorized hardware cannot obtain an IP address or reach internal subnets. Disable unused switch ports, enforce port security through MAC limiting on critical drops, and physically restrict networking closets and public-facing jacks.
Enforce PowerShell Constrained Language Mode, enable Script Block Logging via Event ID 4104, and keep the Antimalware Scan Interface enabled to catch in-memory execution of reconnaissance scripts pulled from GitHub.
Perform SSL/TLS decryption and deep packet inspection on outbound web traffic rather than relying on domain reputation scoring or .gov top-level domain allowlists. This group’s core evasion advantage was staging payloads on legitimate compromised government sites.
Baseline outbound DNS volume and query patterns per host and alert on slow, high-entropy, or delegated-subdomain query chains. MILDFROST uses DNS as a covert fallback channel that survives HTTP-layer blocking.
Mandate a centralized secrets manager such as HashiCorp Vault with full access logging, and remove plaintext keys from code and CI/CD pipeline configuration. This group specifically mines CI/CD environments for pipeline credentials, API keys, and cloud access tokens.
Potential MITRE ATT&CK TTPs
Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| SHA256 | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec,2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a,c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a,6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb,f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f,51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6,d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66,447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8 |
| URLs | hxxps[:]//procon[.]go[.]gov[.]br/ComprovantePDF[.]exe,hxxps[:]//cmgovernadorluizrocha[.]ma[.]gov[.]br/Comprovantepdf[.]exe,hxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/ti[.]zip,hxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/notepadd[.]exe,hxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/tes[.]exe,hxxps[:]//minacu[.]go[.]gov[.]br/ComprovantePDF[.]exe,hxxps[:]//conseg[.]ssp[.]go[.]gov[.]br/COAF-POLICIAFEDERAL[.]exe,hxxps[:]//conseg[.]ssp[.]go[.]gov[.]br/ComprovanteBBpix[.]exe,hxxps[:]//suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/attvpn[.]zip,hxxps[:]//suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/1[.]exe,hxxps[:]//tisup[.]camaratunapolis[.]sc[.]gov[.]br/SoftEther[.]exe,hxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br/files/s[.]zip,hxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br[:]443/files/s[.]exe,hxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br/files/a[.]exe,hxxps[:]//servicos[.]salto[.]sp[.]gov[.]br/j[.]jar,hxxps[:]//www[.]mrtb[.]gov[.]ng/apps/attvpn[.]vip,hxxp[:]//credeb[.]gov[.]gn/r[.]zip,hxxps[:]//sit[.]baer[.]gob[.]ve/r[.]exe,hxxps[:]//jmcov[.]gov[.]py/cxv[.]exe |
| Filenames | ComprovantePDF.exe,Comprovantepdf.exe,COAF-POLICIAFEDERAL.exe,ComprovanteBBpix.exe,SoftEther.exe,notepadd.exe,tes.exe,ti.zip,attvpn.zip,attvpn.vip,1.exe,s.zip,s.exe,a.exe,j.jar,r.zip,r.exe,cxv.exe,DnsCommandBeacon.class |
References
- cloud.google.com — Financially motivated threat actor BREEZE COMET targets Brazil
- crowdstrike.com — PLUMP SPIDER adversary profile
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
