BREEZE COMET Uses Custom Malware to Target Brazil’s Financial Systems

Summary
Mandiant details BREEZE COMET’s intrusions into Brazilian financial and related organizations, including custom malware, compromised websites, credential theft, and fraudulent transfers, and provides indicators and defensive recommendations.
Key points
- Mandiant says BREEZE COMET has targeted Brazilian financial services, retail, and e-commerce organizations since 2024 to manipulate banking software and payment systems for fraudulent transfers.
- Initial access methods include password spraying, voice phishing that leads users to install remote-management tools, compromised websites hosting malware, rogue hardware on retail networks, and reported exploitation of JBoss AS vulnerabilities.
- The group steals credentials and cloud secrets, including CI/CD credentials, API keys, and mTLS credentials used to authenticate financial transactions.
- Custom tools include COBALTSPIN, a Rust SOCKS5 tunneler, and Java, Nim, and Go backdoors used for covert access and persistence.
- Mandiant observed two waves of hundreds of fraudulent transactions within 24–48 hours after access to core financial applications; the article says at least one heist stole tens of thousands of dollars in assets.
- The group disables Windows Defender monitoring and clears logs; Mandiant also found evidence that it used generative AI to accelerate custom script development.
- The article provides IOCs, YARA rules, detection references, and recommendations including application control, phishing-resistant MFA, network segmentation, and tighter Kubernetes and secrets-management controls.
Article Details
- Attack Vectors
- Password spraying and voice phishing impersonating IT support to induce users to install RMM tools.
- Use of compromised municipal and government websites to stage and deliver malware and facilitate social engineering and C2.
- Connection of rogue hardware devices to retail network ports.
- Exploitation of vulnerabilities in JBoss AS servers, as reported by Trend Micro.
- Credential and token theft from CI/CD environments, including hard-coded pipeline credentials, API keys, and privileged cloud access tokens.
- Lateral movement through hijacked service accounts using RDP and SMB.
- Deployment of malicious Kubernetes pods to maintain access and steal cloud secrets.
- Defensive Notes
- Use application control to block execution from user-writable directories and audit portable RMM tools and unapproved service or daemon registrations.
- Train users to recognize social engineering impersonating IT support.
- Deploy 802.1X network access control, disable unused switch ports, enforce port security, and physically secure network equipment and public-facing jacks.
- Enforce PowerShell Constrained Language Mode, Script Block Logging, and AMSI; restrict administrative utilities and monitor volume shadow copy activity.
- Require phishing-resistant MFA and account lockout controls across external portals.
- Inspect outbound traffic with TLS decryption and deep packet inspection; restrict nonessential egress and tunneling, and segment SMB and RDP traffic.
- Apply least-privilege Kubernetes RBAC, admission controls, pod security policies, and egress network policies.
- Use centralized secrets management with access logging, remove plaintext keys from code, and micro-segment financial workloads.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | dontpad[.]com | Paste site used to exfiltrate stolen cloud secrets. |
| SHA256 | 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a | File indicator associated with REALBREEZE in the article's IOC table. |
| SHA256 | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec | File indicator associated with COBALTSPIN in the article's IOC table. |
| SHA256 | 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8 | File indicator listed in the article's IOC table. |
| SHA256 | 51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6 | File indicator associated with XWORM in the article's IOC table. |
| SHA256 | 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb | File indicator associated with BOATBEAM in the article's IOC table. |
| SHA256 | c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a | File indicator associated with MILDFROST in the article's IOC table. |
| SHA256 | d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66 | File indicator listed in the article's IOC table. |
| SHA256 | f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f | File indicator associated with KICKPLATE in the article's IOC table. |
| URL | hxxp[:]//credeb[.]gov[.]gn/r[.]zip | File-delivery URL hosted on a compromised government website. |
| URL | hxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/notepadd[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/tes[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/ti[.]zip | File-delivery URL hosted on a compromised government website. |
| URL | hxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br:443/files/s[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br/files/a[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br/files/s[.]zip | File-delivery URL hosted on a compromised government website. |
| URL | hxxps[:]//cmgovernadorluizrocha[.]ma[.]gov[.]br/Comprovantepdf[.]exe | Malware staging URL on a compromised government website. |
| URL | hxxps[:]//conseg[.]ssp[.]go[.]gov[.]br/COAF-POLICIAFEDERAL[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxps[:]//conseg[.]ssp[.]go[.]gov[.]br/ComprovanteBBpix[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxps[:]//jmcov[.]gov[.]py/cxv[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxps[:]//minacu[.]go[.]gov[.]br/ComprovantePDF[.]exe | Malware staging URL on a compromised government website. |
| URL | hxxps[:]//procon[.]go[.]gov[.]br/ComprovantePDF[.]exe | Malware staging URL on a compromised government website. |
| URL | hxxps[:]//servicos[.]salto[.]sp[.]gov[.]br/j[.]jar | Java archive hosted on a compromised government website. |
| URL | hxxps[:]//sit[.]baer[.]gob[.]ve/r[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxps[:]//suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/1[.]exe | Executable-delivery URL hosted on a compromised government website. |
| URL | hxxps[:]//suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/attvpn[.]zip | VPN-related archive hosted on a compromised government website. |
| URL | hxxps[:]//tisup[.]camaratunapolis[.]sc[.]gov[.]br/SoftEther[.]exe | VPN installer hosted on a compromised government website. |
| URL | hxxps[:]//www[.]mrtb[.]gov[.]ng/apps/attvpn[.]vip | VPN-related payload hosted on a compromised government website. |
MITRE ATT&CK
T1021.001 · Remote Desktop ProtocolThe actor used hijacked service accounts to initiate unauthorized RDP sessions.T1021.002 · SMB/Windows Admin SharesThe actor executed commands through SMB network file shares and enumerated SMB pathways.T1046 · Network Service DiscoveryThe actor ran network scanning tools across internal subnets to identify available SMB pathways.T1053.005 · Scheduled TaskThe actor used scheduled tasks through schtasks.exe running as SYSTEM.T1059.001 · PowerShellReconnaissance utilities were executed in memory via PowerShell, and PowerShell commands were used to disable Defender real-time monitoring.T1070.001 · Clear Windows Event LogsThe actor cleared event logs across compromised hosts to conceal activity.T1090 · ProxyCOBALTSPIN provided a reverse SOCKS5 proxy over WebSocket to route traffic between C2 and internal targets.T1110.003 · Password SprayingBREEZE COMET used password spraying during early compromises.T1219 · Remote Access ToolsThe actor used RMM tools such as AnyDesk to maintain access and establish footholds.T1543.003 · Windows ServiceKICKPLATE silently modified Windows services.T1547.001 · Registry Run Keys / Startup FolderKICKPLATE updated registry startup keys to maintain host-level persistence.T1547.009 · Shortcut ModificationThe actor modified malicious shortcut files in user startup folders.T1552.001 · Credentials In FilesThe actor searched CI/CD environments for hard-coded pipeline credentials and searched files and environment variables for mTLS credentials and certificates.T1562.001 · Disable or Modify ToolsThe actor disabled Windows Defender real-time monitoring on compromised hosts.T1566.004 · Spearphishing VoiceThe actor used voice calls impersonating IT support to persuade users to install RMM tools.T1567.003 · Exfiltration to Text Storage SitesThe actor exfiltrated cloud secrets to the public paste site dontpad[.]com.T1610 · Deploy ContainerThe actor deployed malicious Kubernetes pods to maintain persistence and steal cloud secrets.
Threat Actors
BREEZE COMETFinancially motivated threat actor tracked by GTIG; the article states it was formerly tracked as UNC5669.Plump SpiderName used in public reporting for operations that overlap with BREEZE COMET activity.SHADOW-AETHER-064Name used in public reporting for operations that overlap with BREEZE COMET activity.UNC5669Former tracking name for BREEZE COMET, as stated by GTIG.
Malware
BOATBEAMBOATBEAM: Adding a final layer to their redundant architecture, BREEZE COMET deploys BOATBEAM, a Golang backdoor that initiates a fake IIS HTTPS server on port 443.COBALTSPINTo maneuver through segmented financial networks and bypass strict internal firewalls, BREEZE COMET deploys specialized routing malware: COBALTSPIN.KICKPLATEKICKPLATE: To continuously deliver auxiliary payloads and enforce host-level persistence, BREEZE COMET uses KICKPLATE.LIGHTPAINTLIGHTPAINT: This custom Java-based backdoor is specifically designed to install a legitimate VPN, such as SoftEther, and configure it for automated persistence.MILDFROSTMILDFROST: Operating as a passive Java JAR backdoor hiding inside the JVM process space, MILDFROST uses classes like DnsCommandBeacon.class to establish slow, covert DNS tunnels.XWormdisguised as legitimate tax or receipt documents (e.g., ComprovantePDF.exe), or backdoors such as XWORM set to persist via automated startup shortcut modifications.
Products
Active DirectoryPersistent access to multiple accounts in targeted organizations’ Active Directory and/or cloud environments.BoletoBREEZE COMET operations target organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto.JBoss ASTrend Micro has reported that the group also exploited vulnerabilities in JBoss AS servers to gain initial access.KubernetesIn 2025, BREEZE COMET also deployed malicious Kubernetes pods to maintain persistence and steal cloud secrets, exfiltrating them to public facing notepad websites (such as dontpad[.]com).PixBREEZE COMET operations target organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto.SoftEtherLIGHTPAINT: This custom Java-based backdoor is specifically designed to install a legitimate VPN, such as SoftEther, and configure it for automated persistence.STRBREEZE COMET operations target organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto.Windows DefenderTo protect this access, GTIG observed BREEZE COMET programmatically adding inbound Windows Defender Firewall rules to allow all traffic from the deployed VPN manager, while subsequently clearing the Windows Networking
Tools
ADReconBREEZE COMET used publicly available reconnaissance utilities such as Impacket, ADRecon and ADVipscan, as well as with custom malware, often profiting from environments with low observability.ADVipscanBREEZE COMET used publicly available reconnaissance utilities such as Impacket, ADRecon and ADVipscan, as well as with custom malware, often profiting from environments with low observability.AnyDeskIT support teams to convince users to install Remote Monitoring and Management (RMM) tools such as AnyDesk.ImpacketBREEZE COMET used publicly available reconnaissance utilities such as Impacket, ADRecon and ADVipscan, as well as with custom malware, often profiting from environments with low observability.netcatFrom this initial network access, BREEZE COMET moved laterally to internal systems then downloaded the Netcat utility alongside custom scripts to pull down subsequent post-exploitation frameworks from external openPowerShellThese utilities were often observed being downloaded from GitHub repositories and executed in memory via PowerShell for defense evasion.REALBREEZEThe threat actor deployed the custom LDAP brute-forcing utility REALBREEZE.schtasks.exeThe group supplements KICKPLATE by abusing native scheduled tasks (schtasks.exe running as SYSTEM) and malicious shortcut (.lnk) modifications in user startup folders.
Countries
Brazila financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.GhanaGTIG also observed BREEZE COMET replicating this behavior with municipal domains in Nigeria, Paraguay, Ghana, and Venezuela, suggesting a potentially growing targeting focus.NigeriaGTIG also observed BREEZE COMET replicating this behavior with municipal domains in Nigeria, Paraguay, Ghana, and Venezuela, suggesting a potentially growing targeting focus.ParaguayGTIG also observed BREEZE COMET replicating this behavior with municipal domains in Nigeria, Paraguay, Ghana, and Venezuela, suggesting a potentially growing targeting focus.VenezuelaGTIG also observed BREEZE COMET replicating this behavior with municipal domains in Nigeria, Paraguay, Ghana, and Venezuela, suggesting a potentially growing targeting focus.
Industries
E-commerceBeginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations.Financial ServicesBeginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations.Financial TechnologyThis typically includes banks, payment processors, retailers, exchanges, as well as fintech and banking software providers.GovernmentIn mid-2025, GTIG observed BREEZE COMET using compromised Brazilian small government websites to stage RMM tools, infostealers disguised as legitimate tax or receipt documents (e.g., ComprovantePDF.exe), or backdoorsRetailBeginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations.