Executive Summary

Breeze Comet (formerly UNC5669) represents Brazil's most sophisticated cybercrime group, systematically infiltrating financial institutions across Brazil and expanding globally since 2024. The group employs advanced tactics including insider recruitment, physical network access via rogue hardware, and exploitation of compromised government websites as trusted attack vectors. Using custom malware like CobaltSpin, RealBreeze, and KickPlate, they penetrate segmented financial networks to directly manipulate payment systems including Brazil's Pix instant payment platform, executing hundreds of fraudulent transactions worth tens of thousands of dollars within 24-48 hours of system compromise.

This incident highlights the evolution of financially-motivated cybercrime from traditional ransomware and fraud schemes to direct payment system manipulation. As instant payment systems proliferate globally and threat actors increasingly leverage AI for malware development, Breeze Comet's successful model poses significant risks to financial infrastructure worldwide, particularly in regions with similar digital payment architectures.

Why This Matters Now

Financial institutions globally are rapidly adopting instant payment systems similar to Brazil's Pix, creating new attack surfaces that sophisticated groups like Breeze Comet are actively exploiting. Their successful model of direct payment manipulation represents a paradigm shift in cybercrime that threatens the integrity of digital financial infrastructure worldwide.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Breeze Comet uses multiple vectors including password spraying, vishing calls, insider recruitment, physical hardware implants in retail locations, and exploitation of compromised government websites as trusted domains for social engineering.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely have constrained Breeze Comet's multi-vector attacks by implementing network segmentation and controlled access paths. The group's ability to move laterally from retail networks to financial systems would have been significantly reduced through east-west traffic controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network access from compromised retail endpoints would likely have been restricted to authorized services only, reducing the attackers' ability to discover and access broader corporate infrastructure from their initial footholds.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Access to directory services would likely have been constrained through identity-aware controls, potentially limiting the scope of LDAP brute force attempts and reducing the blast radius of service manipulation activities.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-network movement from retail to financial systems would likely have been blocked or significantly constrained, limiting the attackers' ability to establish tunneling connections across network segments without explicit authorization.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Unauthorized VPN installations and external tunnel communications would likely have been detected and constrained through centralized visibility, reducing the attackers' ability to maintain persistent command channels across the infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized access to external payment systems would likely have been constrained through controlled egress policies, potentially limiting the scope and frequency of fraudulent transaction attempts across multiple payment platforms.

Impact (Mitigations)

While some financial impact may still occur within authorized access boundaries, the scope of theft would likely be significantly reduced due to constrained network reach and limited access to payment system infrastructure.

Impact at a Glance

Affected Business Functions

  • Digital Payment Processing (Pix, Boleto)
  • Real-Time Fund Transfers
  • Customer Transaction Authorization
  • Financial Fraud Detection Systems
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Financial transaction data, customer payment credentials, banking system access tokens, and internal network architecture information of Brazilian financial institutions including banks, fintech companies, and retail payment processors

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement from compromised retail endpoints to critical financial systems
  • Deploy East-West Traffic Security controls with workload-to-workload inspection to detect and block malicious tunneling tools like CobaltSpin moving between network segments
  • Enforce Egress Security & Policy Enforcement with FQDN filtering and data loss prevention to block unauthorized outbound connections and detect financial transaction anomalies
  • Enable Multicloud Visibility & Control with centralized policy and traffic observability to identify suspicious automation, repeated malformed requests, and anomalous financial system interactions
  • Activate Threat Detection & Anomaly Response capabilities with behavioral baselining to detect remote access tools like RMM software and custom malware communications patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image