BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers
ID: 1ad11d66-81e0-5a18-a456-1d932bc04d4d
STIX ID: report--1ad11d66-81e0-5a18-a456-1d932bc04d4d
Feed Name: cybersecurityNews.com
BREEZE COMET (aka UNC5669) is an active financially motivated threat actor targeting Brazilian banks, payment rails (Pix, STR, Boleto) and retail/commerce systems to fraudulently submit transfers via trusted channels. The group uses credential attacks, voice phishing, compromised public sites and rogue hardware to gain access; deploys custom malware and tunneling tools (COBALTSPIN, LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM) often accelerated by generative AI for discovery and credential testing; and has executed rapid fraudulent transaction waves within 24–48 hours. The report includes IoCs (SHA-256 hashes, malicious URLs, filenames, domains) and actionable defensive guidance for remote management controls, network access controls, cloud secret hygiene and monitoring indicators like suspicious PowerShell, DNS tunneling and unexpected payment API activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
