Executive Summary

Since 2024, the financially motivated threat actor Breeze Comet (formerly UNC5669) has targeted Brazilian financial services, retail, and e-commerce organizations through sophisticated payment system manipulation attacks. The group gains initial access via password spraying and social engineering calls impersonating IT support to install remote access tools like AnyDesk, then deploys custom malware including COBALTSPIN, LIGHTPAINT, and MILDFROST to maintain persistence and lateral movement. Successfully executing hundreds of fraudulent transactions worth tens of thousands of dollars, the group specifically targets entities with access to Brazil's National Financial System Network and payment platforms like Pix, STR, and Boleto.

This campaign represents a significant evolution in Latin American cybercrime from opportunistic retail fraud to direct targeting of core financial infrastructure. The threat actor's use of AI-assisted malware development and expansion into other Latin American and African countries signals a new model for financially motivated attacks that defenders must prepare for as interconnected payment ecosystems become increasingly vulnerable.

Why This Matters Now

Breeze Comet's shift from traditional retail banking fraud to direct payment infrastructure attacks represents a dangerous evolution in financial cybercrime, amplified by AI-assisted malware development that accelerates attack timelines and threatens the stability of interconnected global payment systems.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The group used password spraying attacks and social engineering calls impersonating IT support to trick victims into installing remote access tools like AnyDesk, then deployed custom malware for persistence and lateral movement.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain Breeze Comet's lateral movement through financial networks and reduce blast radius by enforcing workload segmentation and identity-aware routing. Multi-stage privilege escalation and cross-environment access would face significant restrictions through east-west traffic controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security fabric could likely limit the scope of initial compromise by restricting network reachability from externally accessible JBoss servers to internal financial systems and development environments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero Trust segmentation would likely constrain cross-environment privilege escalation by limiting reachability between development, cloud, and production financial systems, reducing the scope of credential harvesting activities.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely constrain unauthorized RDP and SMB lateral movement by blocking non-essential inter-workload communications and reducing attacker reachability to core financial API systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility and control mechanisms would likely reduce the effectiveness of distributed C2 communications by constraining outbound connectivity patterns and limiting backdoor deployment across cloud and hybrid environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security controls would likely constrain data exfiltration by blocking unauthorized outbound connections to public file-sharing websites and limiting the scope of credential theft from cloud environments.

Impact (Mitigations)

Despite segmentation controls, attackers with compromised privileged accounts may still access payment systems, though the scope of fraudulent transactions would likely be reduced through constrained lateral reach and limited blast radius.

Impact at a Glance

Affected Business Functions

  • Payment Processing Systems
  • Core Banking Operations
  • Financial Transaction APIs
  • Anti-Fraud Systems
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Compromised Active Directory credentials, cloud secrets, mTLS authentication certificates, and access to National Financial System Network (RSFN) enabling unauthorized payment system access and fraudulent transaction execution

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies and microsegmentation to prevent lateral movement from initial compromise points to critical financial API infrastructure
  • Deploy Egress Security & Policy Enforcement controls with FQDN filtering to block exfiltration to unauthorized destinations like public notepad websites and prevent data loss
  • Enable East-West Traffic Security monitoring to detect and block unauthorized RDP sessions, SMB communications, and suspicious workload-to-workload traffic patterns
  • Establish Multicloud Visibility & Control with centralized policy management to detect anomalous interactions, repeated malformed requests, and suspicious automation targeting payment systems
  • Implement Encrypted Traffic (HPE) controls with high-performance encryption for data in transit to protect financial API communications and prevent interception of mTLS credentials

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image