BREEZE COMET Uses Custom Malware to Target Brazil’s Financial Systems

· Original article ↗

Summary

Mandiant details BREEZE COMET’s intrusions into Brazilian financial and related organizations, including custom malware, compromised websites, credential theft, and fraudulent transfers, and provides indicators and defensive recommendations.

Key points

  • Mandiant says BREEZE COMET has targeted Brazilian financial services, retail, and e-commerce organizations since 2024 to manipulate banking software and payment systems for fraudulent transfers.
  • Initial access methods include password spraying, voice phishing that leads users to install remote-management tools, compromised websites hosting malware, rogue hardware on retail networks, and reported exploitation of JBoss AS vulnerabilities.
  • The group steals credentials and cloud secrets, including CI/CD credentials, API keys, and mTLS credentials used to authenticate financial transactions.
  • Custom tools include COBALTSPIN, a Rust SOCKS5 tunneler, and Java, Nim, and Go backdoors used for covert access and persistence.
  • Mandiant observed two waves of hundreds of fraudulent transactions within 24–48 hours after access to core financial applications; the article says at least one heist stole tens of thousands of dollars in assets.
  • The group disables Windows Defender monitoring and clears logs; Mandiant also found evidence that it used generative AI to accelerate custom script development.
  • The article provides IOCs, YARA rules, detection references, and recommendations including application control, phishing-resistant MFA, network segmentation, and tighter Kubernetes and secrets-management controls.

Article Details

Attack Vectors
  • Password spraying and voice phishing impersonating IT support to induce users to install RMM tools.
  • Use of compromised municipal and government websites to stage and deliver malware and facilitate social engineering and C2.
  • Connection of rogue hardware devices to retail network ports.
  • Exploitation of vulnerabilities in JBoss AS servers, as reported by Trend Micro.
  • Credential and token theft from CI/CD environments, including hard-coded pipeline credentials, API keys, and privileged cloud access tokens.
  • Lateral movement through hijacked service accounts using RDP and SMB.
  • Deployment of malicious Kubernetes pods to maintain access and steal cloud secrets.
Defensive Notes
  • Use application control to block execution from user-writable directories and audit portable RMM tools and unapproved service or daemon registrations.
  • Train users to recognize social engineering impersonating IT support.
  • Deploy 802.1X network access control, disable unused switch ports, enforce port security, and physically secure network equipment and public-facing jacks.
  • Enforce PowerShell Constrained Language Mode, Script Block Logging, and AMSI; restrict administrative utilities and monitor volume shadow copy activity.
  • Require phishing-resistant MFA and account lockout controls across external portals.
  • Inspect outbound traffic with TLS decryption and deep packet inspection; restrict nonessential egress and tunneling, and segment SMB and RDP traffic.
  • Apply least-privilege Kubernetes RBAC, admission controls, pod security policies, and egress network policies.
  • Use centralized secrets management with access logging, remove plaintext keys from code, and micro-segment financial workloads.

Indicators of compromise

TypeIndicatorContext
DOMAINdontpad[.]comPaste site used to exfiltrate stolen cloud secrets.
SHA2562214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439aFile indicator associated with REALBREEZE in the article's IOC table.
SHA2563b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceecFile indicator associated with COBALTSPIN in the article's IOC table.
SHA256447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8File indicator listed in the article's IOC table.
SHA25651fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6File indicator associated with XWORM in the article's IOC table.
SHA2566d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6cebFile indicator associated with BOATBEAM in the article's IOC table.
SHA256c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78aFile indicator associated with MILDFROST in the article's IOC table.
SHA256d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66File indicator listed in the article's IOC table.
SHA256f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4fFile indicator associated with KICKPLATE in the article's IOC table.
URLhxxp[:]//credeb[.]gov[.]gn/r[.]zipFile-delivery URL hosted on a compromised government website.
URLhxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/notepadd[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/tes[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxp[:]//gcm[.]setelagoas[.]mg[.]gov[.]br/files/ti[.]zipFile-delivery URL hosted on a compromised government website.
URLhxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br:443/files/s[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br/files/a[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxp[:]//suporte[.]ourinhos[.]sp[.]gov[.]br/files/s[.]zipFile-delivery URL hosted on a compromised government website.
URLhxxps[:]//cmgovernadorluizrocha[.]ma[.]gov[.]br/Comprovantepdf[.]exeMalware staging URL on a compromised government website.
URLhxxps[:]//conseg[.]ssp[.]go[.]gov[.]br/COAF-POLICIAFEDERAL[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxps[:]//conseg[.]ssp[.]go[.]gov[.]br/ComprovanteBBpix[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxps[:]//jmcov[.]gov[.]py/cxv[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxps[:]//minacu[.]go[.]gov[.]br/ComprovantePDF[.]exeMalware staging URL on a compromised government website.
URLhxxps[:]//procon[.]go[.]gov[.]br/ComprovantePDF[.]exeMalware staging URL on a compromised government website.
URLhxxps[:]//servicos[.]salto[.]sp[.]gov[.]br/j[.]jarJava archive hosted on a compromised government website.
URLhxxps[:]//sit[.]baer[.]gob[.]ve/r[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxps[:]//suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/1[.]exeExecutable-delivery URL hosted on a compromised government website.
URLhxxps[:]//suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/attvpn[.]zipVPN-related archive hosted on a compromised government website.
URLhxxps[:]//tisup[.]camaratunapolis[.]sc[.]gov[.]br/SoftEther[.]exeVPN installer hosted on a compromised government website.
URLhxxps[:]//www[.]mrtb[.]gov[.]ng/apps/attvpn[.]vipVPN-related payload hosted on a compromised government website.

MITRE ATT&CK

T1021.001 · Remote Desktop ProtocolThe actor used hijacked service accounts to initiate unauthorized RDP sessions.T1021.002 · SMB/Windows Admin SharesThe actor executed commands through SMB network file shares and enumerated SMB pathways.T1046 · Network Service DiscoveryThe actor ran network scanning tools across internal subnets to identify available SMB pathways.T1053.005 · Scheduled TaskThe actor used scheduled tasks through schtasks.exe running as SYSTEM.T1059.001 · PowerShellReconnaissance utilities were executed in memory via PowerShell, and PowerShell commands were used to disable Defender real-time monitoring.T1070.001 · Clear Windows Event LogsThe actor cleared event logs across compromised hosts to conceal activity.T1090 · ProxyCOBALTSPIN provided a reverse SOCKS5 proxy over WebSocket to route traffic between C2 and internal targets.T1110.003 · Password SprayingBREEZE COMET used password spraying during early compromises.T1219 · Remote Access ToolsThe actor used RMM tools such as AnyDesk to maintain access and establish footholds.T1543.003 · Windows ServiceKICKPLATE silently modified Windows services.T1547.001 · Registry Run Keys / Startup FolderKICKPLATE updated registry startup keys to maintain host-level persistence.T1547.009 · Shortcut ModificationThe actor modified malicious shortcut files in user startup folders.T1552.001 · Credentials In FilesThe actor searched CI/CD environments for hard-coded pipeline credentials and searched files and environment variables for mTLS credentials and certificates.T1562.001 · Disable or Modify ToolsThe actor disabled Windows Defender real-time monitoring on compromised hosts.T1566.004 · Spearphishing VoiceThe actor used voice calls impersonating IT support to persuade users to install RMM tools.T1567.003 · Exfiltration to Text Storage SitesThe actor exfiltrated cloud secrets to the public paste site dontpad[.]com.T1610 · Deploy ContainerThe actor deployed malicious Kubernetes pods to maintain persistence and steal cloud secrets.

Threat Actors

Malware

Products

Tools

Countries

Industries

Related Articles