Executive Summary
Since 2024, the financially motivated threat actor Breeze Comet (formerly UNC5669) has targeted Brazilian financial services, retail, and e-commerce organizations through sophisticated payment system manipulation attacks. The group gains initial access via password spraying and social engineering calls impersonating IT support to install remote access tools like AnyDesk, then deploys custom malware including COBALTSPIN, LIGHTPAINT, and MILDFROST to maintain persistence and lateral movement. Successfully executing hundreds of fraudulent transactions worth tens of thousands of dollars, the group specifically targets entities with access to Brazil's National Financial System Network and payment platforms like Pix, STR, and Boleto.
This campaign represents a significant evolution in Latin American cybercrime from opportunistic retail fraud to direct targeting of core financial infrastructure. The threat actor's use of AI-assisted malware development and expansion into other Latin American and African countries signals a new model for financially motivated attacks that defenders must prepare for as interconnected payment ecosystems become increasingly vulnerable.
Why This Matters Now
Breeze Comet's shift from traditional retail banking fraud to direct payment infrastructure attacks represents a dangerous evolution in financial cybercrime, amplified by AI-assisted malware development that accelerates attack timelines and threatens the stability of interconnected global payment systems.
Attack Path Analysis
Breeze Comet initiated access through password spraying attacks and social engineering calls impersonating IT support to install RMM tools like AnyDesk, while also exploiting vulnerable JBoss AS servers. The threat actor escalated privileges using custom LDAP brute-forcing tools and targeted development/cloud environments to steal mTLS credentials and gain Active Directory access. Lateral movement occurred through unauthorized RDP sessions, SMB file shares, and deployment of COBALTSPIN routing malware to establish persistent network tunnels. Command and control was maintained using compromised Brazilian government websites as C2 endpoints and multiple custom backdoors including LIGHTPAINT, MILDFROST, and KICKPLATE. The group exfiltrated cloud secrets to public notepad websites and accessed core financial applications to execute hundreds of fraudulent transactions through Pix, STR, and Boleto payment systems. Finally, they cleared event logs and deleted operational directories to minimize forensic traces while completing unauthorized financial transfers worth tens of thousands of dollars.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors gained initial access through password spraying attacks against financial institutions and social engineering phone calls impersonating IT support to trick victims into installing AnyDesk RMM tools. They also exploited vulnerable JBoss AS servers to deploy web shells for follow-on exploitation.
MITRE ATT&CK® Techniques
Password Spraying
Spearphishing Attachment
Exploit Public-Facing Application
Remote Access Software
Remote Desktop Protocol
Domain Account
Disable or Modify Tools
Clear Windows Event Logs
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-factor Authentication for All Access
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Centralized Identity Management
Control ID: Identity Function 2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Information Security in Project Management
Control ID: A.8.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Primary target for Breeze Comet's payment system manipulation attacks, with direct exposure to fraudulent transactions through banking APIs, Pix systems, and financial infrastructure compromises.
Banking/Mortgage
Critical vulnerability to mTLS credential theft and National Financial System Network access exploitation, enabling unauthorized transaction execution and financial fraud at institutional scale.
Retail Industry
Exposed through rogue hardware device insertion into store networks and payment processor compromises, facilitating lateral movement to internal systems and financial transaction fraud.
Information Technology/IT
Targeted through social engineering impersonation attacks and RMM tool deployment, with cloud infrastructure compromises enabling persistent access and financial system manipulation capabilities.
Sources
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systemshttps://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.htmlVerified
- Google Cloud Blog - Financially motivated threat actor Breeze Comet targets Brazilhttps://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/Verified
- Axur reveals Plump Spider modus operandi systemic Pix fraudhttps://blog.axur.com/en-us/axur-reveals-plump-spider-modus-operandi-systemic-pix-fraudVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain Breeze Comet's lateral movement through financial networks and reduce blast radius by enforcing workload segmentation and identity-aware routing. Multi-stage privilege escalation and cross-environment access would face significant restrictions through east-west traffic controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric could likely limit the scope of initial compromise by restricting network reachability from externally accessible JBoss servers to internal financial systems and development environments.
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely constrain cross-environment privilege escalation by limiting reachability between development, cloud, and production financial systems, reducing the scope of credential harvesting activities.
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely constrain unauthorized RDP and SMB lateral movement by blocking non-essential inter-workload communications and reducing attacker reachability to core financial API systems.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control mechanisms would likely reduce the effectiveness of distributed C2 communications by constraining outbound connectivity patterns and limiting backdoor deployment across cloud and hybrid environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security controls would likely constrain data exfiltration by blocking unauthorized outbound connections to public file-sharing websites and limiting the scope of credential theft from cloud environments.
Despite segmentation controls, attackers with compromised privileged accounts may still access payment systems, though the scope of fraudulent transactions would likely be reduced through constrained lateral reach and limited blast radius.
Impact at a Glance
Affected Business Functions
- Payment Processing Systems
- Core Banking Operations
- Financial Transaction APIs
- Anti-Fraud Systems
Estimated downtime: 7 days
Estimated loss: $50,000
Compromised Active Directory credentials, cloud secrets, mTLS authentication certificates, and access to National Financial System Network (RSFN) enabling unauthorized payment system access and fraudulent transaction execution
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement from initial compromise points to critical financial API infrastructure
- • Deploy Egress Security & Policy Enforcement controls with FQDN filtering to block exfiltration to unauthorized destinations like public notepad websites and prevent data loss
- • Enable East-West Traffic Security monitoring to detect and block unauthorized RDP sessions, SMB communications, and suspicious workload-to-workload traffic patterns
- • Establish Multicloud Visibility & Control with centralized policy management to detect anomalous interactions, repeated malformed requests, and suspicious automation targeting payment systems
- • Implement Encrypted Traffic (HPE) controls with high-performance encryption for data in transit to protect financial API communications and prevent interception of mTLS credentials



