Hackers Breach Brazilian Financial Firms and Execute Hundreds of Fraudulent Transactions
ID: 90b1f2e7-0d48-58f8-9f9b-fa7b7d334d4a
STIX ID: report--90b1f2e7-0d48-58f8-9f9b-fa7b7d334d4a
Feed Name: GBHackers
BREEZE COMET is a financially motivated actor that has compromised Brazilian banks, payment processors, retailers, and fintechs to obtain privileged access, mTLS credentials, and transaction-signing authorities allowing the group to submit authenticated fraudulent transfers (including via Pix and STR). The report describes reconnaissance techniques, social engineering, RMM abuse, lateral movement, bespoke implants (COBALTSPIN, LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM, XWORM), evidence of multi-wave frauds, and provides hashes as indicators of compromise along with mitigation recommendations for protecting payment certificates, APIs, and detecting tunneling and unauthorized RMM use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
