Executive Summary
Breeze Comet (formerly UNC5669) represents Brazil's most sophisticated cybercrime group, systematically infiltrating financial institutions across Brazil and expanding globally since 2024. The group employs advanced tactics including insider recruitment, physical network access via rogue hardware, and exploitation of compromised government websites as trusted attack vectors. Using custom malware like CobaltSpin, RealBreeze, and KickPlate, they penetrate segmented financial networks to directly manipulate payment systems including Brazil's Pix instant payment platform, executing hundreds of fraudulent transactions worth tens of thousands of dollars within 24-48 hours of system compromise.
This incident highlights the evolution of financially-motivated cybercrime from traditional ransomware and fraud schemes to direct payment system manipulation. As instant payment systems proliferate globally and threat actors increasingly leverage AI for malware development, Breeze Comet's successful model poses significant risks to financial infrastructure worldwide, particularly in regions with similar digital payment architectures.
Why This Matters Now
Financial institutions globally are rapidly adopting instant payment systems similar to Brazil's Pix, creating new attack surfaces that sophisticated groups like Breeze Comet are actively exploiting. Their successful model of direct payment manipulation represents a paradigm shift in cybercrime that threatens the integrity of digital financial infrastructure worldwide.
Attack Path Analysis
Breeze Comet initiated attacks through password spraying, vishing calls, insider recruitment, and physical network access at retail locations. The group escalated privileges using custom malware like RealBreeze for LDAP brute forcing and KickPlate for Windows service manipulation. They moved laterally through poorly segmented networks using CobaltSpin tunneling malware to reach financial systems. Command and control was maintained through legitimate VPN installations and network tunnels to external C2 infrastructure. The group exfiltrated funds directly by accessing Brazilian payment systems (Pix, Boleto, STR) and executing hundreds of fraudulent transactions worth tens of thousands of dollars. Final impact included direct financial theft and potential replication of tactics across global financial institutions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained initial access through multiple vectors including password spraying attacks, vishing calls impersonating IT support to install RMM software, recruitment of malicious insiders, and direct connection of rogue hardware to retail store network ports that successfully obtained IP addresses via DHCP
MITRE ATT&CK® Techniques
Brute Force
Phishing: Spearphishing Attachment
Hardware Additions
Protocol Tunneling
Registry Run Keys / Startup Folder
Remote Services: VNC
Domain Policy Modification
Data Manipulation: Stored Data Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Network Segmentation and Access Controls
Control ID: 11.2.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
Digital Operational Resilience Act (DORA) – ICT Risk Management Framework
Control ID: Article 8
CISA Zero Trust Maturity Model 2.0 – Device Security
Control ID: DE.4
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
GLBA Safeguards Rule – Access Controls on Customer Information Systems
Control ID: 314.4(b)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Direct targets of Breeze Comet's payment infrastructure attacks, vulnerable to custom malware exploiting financial transaction systems like instant payment platforms.
Financial Services
High-risk sector facing sophisticated attacks on payment processing systems, requiring enhanced east-west traffic security and zero trust segmentation controls.
Retail Industry
Vulnerable to physical network infiltration through PoS systems and store networks, enabling lateral movement to corporate financial transaction processing systems.
Government Administration
Municipal websites compromised as staging grounds for social engineering attacks, with inadequate network segmentation enabling privilege escalation and persistence.
Sources
- 'Breeze Comet' Tears Into Brazilian & Global Financial Systemshttps://www.darkreading.com/threat-intelligence/breeze-comet-brazilian-global-financial-systemsVerified
- Google Threat Intelligence Group and Mandiant Research on Breeze Comethttps://cloud.google.com/blog/topics/threat-intelligence/breeze-comet-financial-targetingVerified
- Axur Threat Intelligence Report on Brazilian Financial Cybercrimehttps://axur.com/en/research/breeze-comet-analysis/Verified
- CISA Alert on Financial Sector Threats in Latin Americahttps://www.cisa.gov/news-events/alerts/aa24-250aVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely have constrained Breeze Comet's multi-vector attacks by implementing network segmentation and controlled access paths. The group's ability to move laterally from retail networks to financial systems would have been significantly reduced through east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network access from compromised retail endpoints would likely have been restricted to authorized services only, reducing the attackers' ability to discover and access broader corporate infrastructure from their initial footholds.
Control: Zero Trust Segmentation
Mitigation: Access to directory services would likely have been constrained through identity-aware controls, potentially limiting the scope of LDAP brute force attempts and reducing the blast radius of service manipulation activities.
Control: East-West Traffic Security
Mitigation: Cross-network movement from retail to financial systems would likely have been blocked or significantly constrained, limiting the attackers' ability to establish tunneling connections across network segments without explicit authorization.
Control: Multicloud Visibility & Control
Mitigation: Unauthorized VPN installations and external tunnel communications would likely have been detected and constrained through centralized visibility, reducing the attackers' ability to maintain persistent command channels across the infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized access to external payment systems would likely have been constrained through controlled egress policies, potentially limiting the scope and frequency of fraudulent transaction attempts across multiple payment platforms.
While some financial impact may still occur within authorized access boundaries, the scope of theft would likely be significantly reduced due to constrained network reach and limited access to payment system infrastructure.
Impact at a Glance
Affected Business Functions
- Digital Payment Processing (Pix, Boleto)
- Real-Time Fund Transfers
- Customer Transaction Authorization
- Financial Fraud Detection Systems
Estimated downtime: 2 days
Estimated loss: $50,000
Financial transaction data, customer payment credentials, banking system access tokens, and internal network architecture information of Brazilian financial institutions including banks, fintech companies, and retail payment processors
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement from compromised retail endpoints to critical financial systems
- • Deploy East-West Traffic Security controls with workload-to-workload inspection to detect and block malicious tunneling tools like CobaltSpin moving between network segments
- • Enforce Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to block unauthorized outbound connections and detect financial transaction anomalies
- • Enable Multicloud Visibility & Control with centralized policy and traffic observability to identify suspicious automation, repeated malformed requests, and anomalous financial system interactions
- • Activate Threat Detection & Anomaly Response capabilities with behavioral baselining to detect remote access tools like RMM software and custom malware communications patterns



