logo

BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers

ID: 1ad11d66-81e0-5a18-a456-1d932bc04d4d

STIX ID: report--1ad11d66-81e0-5a18-a456-1d932bc04d4d

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-09-02

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

BREEZE COMET (aka UNC5669) is an active financially motivated threat actor targeting Brazilian banks, payment rails (Pix, STR, Boleto) and retail/commerce systems to fraudulently submit transfers via trusted channels. The group uses credential attacks, voice phishing, compromised public sites and rogue hardware to gain access; deploys custom malware and tunneling tools (COBALTSPIN, LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM) often accelerated by generative AI for discovery and credential testing; and has executed rapid fraudulent transaction waves within 24–48 hours. The report includes IoCs (SHA-256 hashes, malicious URLs, filenames, domains) and actionable defensive guidance for remote management controls, network access controls, cloud secret hygiene and monitoring indicators like suspicious PowerShell, DNS tunneling and unexpected payment API activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.