Breeze Comet, a threat actor previously known as UNC5669, has been targeting Brazilian financial services, retail, and e-commerce sectors since 2024. This group specializes in manipulating payment systems and banking software to execute fraudulent transactions, leading to significant financial losses. The Google Threat Intelligence Group and Mandiant have identified Breeze Comet's operations as overlapping with other threat clusters tracked by CrowdStrike and Trend Micro, known as Plump Spider and SHADOW-AETHER-064 respectively. Operating primarily out of Brazil, the group gains unauthorized access through tactics like password spraying and impersonating IT support via voice calls, convincing targets to install Remote Monitoring and Management tools such as AnyDesk. They also exploit vulnerable JBoss AS servers to deploy web shells for further infiltration.

Breeze Comet targets entities authorized to conduct transactions through systems like Pix, STR, and Boleto, including banks, payment processors, and fintech companies. Their tactics have evolved to include custom malware and compromised websites to facilitate command-and-control operations. The group requires access to the National Financial System Network, mTLS credentials, and various organizational accounts to carry out their operations effectively.

The group employs sophisticated methods such as using a reverse SOCKS5 proxy to navigate firewalls and deploying malicious Kubernetes pods. To maintain persistence, they disable Windows Defender on compromised systems. Breeze Comet's final objective is to access core financial applications and execute numerous fraudulent transactions while erasing evidence. Their use of large language models for streamlined malware development signifies an advanced level of threat.

This shift from retail banking fraud to direct intrusions into financial infrastructures highlights the growing capabilities of threat actors like Breeze Comet. Their activities indicate a broader trend that could influence future cyber threats across Latin America and beyond, posing increased risks to interconnected financial systems.