Actor Profile
Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023. The group specializes in manipulating Brazilian payment systems and banking software to conduct fraudulent transfers, successfully executing heists worth tens of thousands of U.S. dollars. Their operations require sophisticated access to Brazil's National Financial System Network (RSFN), mTLS credentials for Pix/STR payment systems, Active Directory and cloud environment access, and deep understanding of target organizations' transfer processing procedures and anti-fraud systems. Recent infrastructure indicates potential expansion into other Latin American and African countries.
TTPs (Tactics, Techniques, Procedures)
Initial access via password spraying and social engineering (impersonating IT support via voice calls and WhatsApp to deploy RMM tools like AnyDesk, or delivering PowerShell reconnaissance scripts). Exploitation of vulnerable JBoss AS servers to deploy web shells. Compromised Brazilian government websites used for staging malware (XWorm backdoors, infostealers) and C2 infrastructure. Physical access via rogue hardware devices in retail store networks. Internal reconnaissance using Impacket, ADRecon, ADVipscan, and custom LDAP brute-forcing tool REALBREEZE. Lateral movement via unauthorized RDP sessions and SMB file shares. Deployment of custom malware suite including COBALTSPIN (Rust-based SOCKS5 proxy over WebSocket), LIGHTPAINT (Java backdoor installing SoftEther VPN), MILDFROST (passive Java backdoor with DNS tunneling), KICKPLATE (Nim backdoor impersonating Windows Update), and BOATBEAM (Golang backdoor with fake IIS HTTPS server). Persistence via malicious Kubernetes pods and cloud secret theft to public notepad sites. Defense evasion through PowerShell commands disabling Windows Defender. Execution of fraudulent transactions via compromised privileged accounts and COBALTSPIN accessing financial APIs. Event log clearing for anti-forensics.
Targets & Patterns
Primary targets are Brazilian organizations with access to banking software, APIs, and payment systems (Pix, STR, Boleto), including financial services institutions, banks, payment processors, retailers, e-commerce platforms, exchanges, and fintech/banking software providers. The actor specifically seeks entities with permission to conduct transactions through Brazil's National Financial System Network (RSFN). Targeting patterns show expansion beyond Brazil, with compromised infrastructure observed in Nigeria, Paraguay, Ghana, and Venezuela, indicating growing focus on Latin America and Africa. The selection criteria reflect the technical requirements for fraud execution: RSFN access, mTLS credentials, extensive AD/cloud access, and organizations with exploitable transfer processing workflows.
Historical Context
Breeze Comet has been active since September 2023 under the UNC5669 designation, with activity also tracked as Plump Spider (CrowdStrike) and SHADOW-AETHER-064 (Trend Micro). The group's tactics have evolved significantly from 2024 to 2025: initial operations relied on commercial RMM tools for persistence, but by 2025 the actor developed a sophisticated custom malware suite and began deploying malicious Kubernetes pods. An Axur report from November 2025 documented their social engineering techniques via WhatsApp. Google Threat Intelligence Group and Mandiant tracking indicates the campaign has resulted in hundreds of fraudulent transactions across Brazilian payment systems since 2024, with at least one confirmed heist worth tens of thousands of U.S. dollars. Recent infrastructure expansion suggests operational maturation and geographic diversification.
Defensive Recommendations
- Monitor for unauthorized RMM tool installations (AnyDesk, SoftEther VPN) and implement application whitelisting to prevent execution of unapproved remote access software
- Deploy detection rules for custom malware indicators: COBALTSPIN (Rust-based SOCKS5 proxy over WebSocket on non-standard ports), BOATBEAM (fake IIS HTTPS servers on port 443), KICKPLATE (processes impersonating Windows Update Health Tools), MILDFROST (DNS tunneling patterns), and LIGHTPAINT (Java-based backdoor activity)
- Implement robust monitoring of privileged account usage in financial API systems, particularly for Pix, STR, and Boleto payment platforms, with alerting on unusual transaction volumes or patterns
- Harden JBoss AS servers with current patches and deploy web application firewalls to detect web shell deployment attempts; monitor for Chisel and proxy utility execution
- Enable tamper protection for endpoint security solutions to prevent PowerShell-based disabling of Windows Defender real-time monitoring; monitor for event log clearing activity and exfiltration to public notepad sites like dontpad[.]com
- Implement network segmentation to prevent lateral movement via RDP and SMB, enforce multi-factor authentication for all privileged accounts, and monitor for LDAP brute-forcing attempts using tools like REALBREEZE, Impacket, ADRecon, and ADVipscan
- Conduct physical security audits of retail store networks to detect rogue hardware devices and implement network access control (NAC) solutions to prevent unauthorized device connections
---
# Geopolitical Context
Geopolitical Context
Breeze Comet represents a sophisticated financially motivated threat actor operating primarily from Brazil since 2023, targeting the country's digital payment infrastructure including Pix, STR, and Boleto systems. The campaign reflects the maturation of Latin American cybercrime ecosystems, where threat actors demonstrate advanced technical capabilities in manipulating regional financial APIs and payment processors. The group's evolution from basic RMM tool deployment in 2024 to sophisticated malware suites and cloud infrastructure compromise by 2025-2026 illustrates the professionalization of regional e-crime. Infrastructure indicators suggest potential expansion into other Latin American markets (Paraguay, Venezuela) and African nations (Nigeria, Ghana), consistent with targeting Portuguese and Spanish-speaking financial systems with similar regulatory frameworks. This activity underscores vulnerabilities in emerging market digital payment infrastructure as cashless transaction systems rapidly scale across developing economies.
State Actor Alignment
Breeze Comet is assessed as a financially motivated cybercrime group with no apparent state sponsorship. The threat actor is believed to operate from Brazil, according to CrowdStrike reporting. The campaign does not exhibit characteristics consistent with state-directed cyber operations—targeting is opportunistic and profit-driven rather than aligned with strategic intelligence collection or geopolitical objectives. The group's focus on manipulating commercial payment systems for immediate financial gain, combined with their use of commodity malware and publicly available tools, is consistent with organized cybercrime rather than state-backed activity. No sanctions designations or formal government attributions have been reported in connection with this threat actor. The operational pattern suggests a criminal enterprise exploiting regulatory gaps and security weaknesses in Brazil's rapidly expanding digital financial sector.
Business Impacty pro region
The campaign has direct implications for Brazil's financial sector and broader Latin American digital economy. Brazil's Pix instant payment system, launched in 2020 and now processing billions of transactions monthly, represents critical national financial infrastructure—successful manipulation threatens public confidence in digital payment adoption. The threat actor's apparent reconnaissance of infrastructure in Paraguay, Venezuela, Nigeria, and Ghana suggests potential cross-border expansion, which could destabilize trust in emerging market fintech ecosystems across the Global South. For European and North American financial institutions with Brazilian operations or partnerships, the campaign highlights supply chain and third-party risk exposure through compromised payment processors and fintech integrations. The use of compromised Brazilian government websites for malware staging raises concerns about public sector cybersecurity posture in Latin America. If the threat actor successfully expands operations to African markets, it may exploit similar vulnerabilities in mobile money and digital payment platforms that serve as primary financial infrastructure in countries with limited traditional banking penetration.
Forecast
If Breeze Comet continues to refine its operational tradecraft and successfully monetizes intrusions without significant law enforcement disruption, the group is likely to expand targeting across Latin America and potentially into African markets where similar payment system architectures exist. The threat actor's demonstrated capability to compromise cloud environments and deploy persistent backdoors suggests that affected organizations may face prolonged dwell times and repeated intrusion attempts even after initial remediation. If Brazilian financial regulators and law enforcement do not enhance detection capabilities for fraudulent API transactions and mTLS credential abuse, the volume of successful heists is likely to increase. Should the group's infrastructure footprint in Nigeria, Ghana, Paraguay, and Venezuela translate into active operations, regional financial institutions in those countries should anticipate similar social engineering campaigns and payment system manipulation attempts. If international law enforcement coordination improves—particularly between Brazilian Federal Police and counterparts in targeted expansion countries—operational disruption becomes more feasible, though the group's use of redundant backdoors and cloud persistence mechanisms may enable rapid reconstitution of access.
