Google has revealed the group BREEZE COMET, which has been hunting for two years on payment systems Pix, STR and Boleto

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
883
Deposit
0$
Google has revealed cyber-criminal group BREEZE COMET, which instead of hunting for individual bank customers is trying to infiltrate directly into the infrastructure of companies eligible to send payment teams. Since 2024, the group has been attacking banks, fintech companies, payment operators, retailers, exchanges and banking software providers in Brazil to conduct fraudulent transfers through Pix, STR and Boleto.

Google Threat Intelligence Group and Mandiant are tracking BREEZE COMET under the current name instead of the former UNC5669. Activity overlaps with groups other companies called Plump Spider and SHADOW-AETHER-064. To conduct transfers, criminals need access to the Brazilian financial network RSFN, mutual TLS authentication credentials, internal banking applications, Active Directory and cloud infrastructure.

Of particular interest is Pix, the instant payments system of the Central Bank of Brazil. BREEZE COMET searches within networks for certificates, API keys, and other secrets that allow applications to send legitimately signed payment teams. The group also includes STR, a bank reserve transfer system, and Boleto, a popular bill payment mechanism in the country.

At the first stage, BREEZE COMET used spraying passwords and вишингvishing. The criminals called the staff under the guise of IT support and persuaded to install AnyDesk or other remote control. Axur also recorded attempts to recruit employees of banks and companies, offering money and a share of the future theft.


By mid-2025, the scheme had become more complex. The group hacked into Brazil's small state sites and placed remote management tools, infostilers and XWORM disguised as tax documents and receipts on trusted domains. Google has also found similar infrastructure on municipal sites Nigeria, Paraguay, Ghana and Venezuela, which could indicate the preparation of operations outside Brazil.

In some cases, criminals physically connected foreign equipment to retail store networks and then moved to internal systems. Trend Micro has previously linked the intersecting activity of SHADOW-AETHER-064 to the operation of vulnerable JBoss AS servers.

To secure the BREEZE, COMET has developed its own set of tools. COBALTSPIN on Rust builds a reverse SOCKS5 proxy through WebSocket and helps to pass through segmented networks. LIGHTPAINT installs SoftEther VPN, MILDFROST uses hidden DNS tunnels, KICKPLATE maintains constant access through Windows services and scheduler tasks, and BOATBEAM masks the control channel for the regular HTTPS server IIS.

Google has also found signs of the use of generative AI in the development of scripts for intelligence, verification of credentials, mass deployment of tools and extraction of information. The samples obtained by Mandiant looked workmanship and well adapted to specific victims, but contained unusually verbose comments and a uniform structure characteristic of code created by large language models.

After receiving privileged access, the group acts quickly. In one case investigated, BREEZE COMET went to major financial applications 24 to 48 hours later and conducted two waves from hundreds of fraudulent transactions. Google confirms at least one successful asset theft worth tens of thousands of dollars and believes the group's technical capabilities continue to grow.
 
Top Bottom