A cybercrime group known as Breeze Comet is aggressively targeting financial systems in Brazil and potentially beyond, using sophisticated methods to reroute funds into their own accounts. This group focuses on a range of financial entities, including banks, fintech companies, and government organizations. According to recent findings by Google Threat Intelligence Group and Mandiant, Breeze Comet employs custom malware and inventive infiltration techniques to manipulate transaction systems, siphoning off significant amounts of money. Originally identified as UNC5669, the group uses social engineering and direct hardware connections to gain access to networks. They exploit gaps in network segmentation to conduct reconnaissance and expand their influence within targeted networks. To mitigate these threats, experts recommend deploying Network Access Control measures and physically securing network hardware.
The group has recently utilized Brazilian government websites as malware staging grounds, exploiting their credibility to fool more significant targets. This strategy is reportedly being tested in other countries, including Nigeria and Venezuela. Alarmingly, Breeze Comet is also using generative AI to enhance the complexity and scope of their malware, making their operations even more challenging to combat.
Breeze Comet's custom malware suite includes tools like RealBreeze, LightPaint, and KickPlate, which facilitate privilege escalation and network persistence. Their standout tool, CobaltSpin, creates a network tunnel from compromised machines to command-and-control servers, aiming to access financial applications like Brazil's Pix and STR. This deep understanding of Brazil's payment systems allows them to bypass fraud mechanisms effectively.
Zach Edwards from Infoblox emphasizes the need for organizations to monitor for internal network anomalies like unauthorized tunnels and RMM software. He suggests tightening approval processes with measures like two-factor authentication to prevent unauthorized transactions. This threat is rooted in Brazil's history of digital finance and has evolved into a sophisticated cybercrime network, posing a significant threat not only within Latin America but potentially on a global scale.


