Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Breeze Comet: A Sophisticated Malware Actor Exploiting Vulnerabilities in Brazilian Payment Systems




Breeze Comet, a sophisticated malware actor, has been identified as a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil. The actor's tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command-and-control, and to interact with financial software and payment APIs. The actor's operational infrastructure may also indicate intent to expand their infrastructure footprint to other countries in Latin America and Africa. This article provides a detailed analysis of the Breeze Comet actor's tactics, persistence mechanisms, and capabilities, and how these may impact organizations in the financial sector.



  • The Breeze Comet malware actor is a financially motivated threat actor targeting financial entities and companies in Brazil.
  • The actor has been active since September 2023 and uses customized malware and compromised websites to facilitate initial access and interaction with financial software and payment APIs.
  • The actor's tactics have evolved to leverage Kubernetes pods, cloud secrets, and custom backdoors for persistence and lateral movement.
  • The actor uses various tactics to gain initial access, including password spraying, voice calls, and deploying web shells.
  • The actor's persistence mechanisms have evolved to include deploying malicious Kubernetes pods and stealing cloud secrets.
  • The actor uses multiple custom backdoors, including LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, to maintain access and evade detection.
  • The actor's campaigns represent a notable shift in targeting financial organizations and core financial switch and instant payment infrastructure.



  • The threat landscape has recently witnessed the emergence of a sophisticated malware actor known as Breeze Comet, which has been identified as a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil. The actor has been active since 2023, with the Google Threat Intelligence Group (GTIG) and Mandiant teams describing it as "a sophisticated threat actor that has been operating out of Brazil, targeting financial entities and companies offering financial services."

    According to CrowdStrike, the e-crime group, also operating under the monikers Plump Spider and SHADOW-AETHER-064, has been operating out of Brazil and has been active since September 2023. The actor's primary targets are organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto. This covers a wide range of entities, including banks, payment processors, retailers, and exchanges, not to mention fintech and banking software providers.

    The Breeze Comet actor's tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command-and-control (C2), and to interact with financial software and payment APIs. The actor's operational infrastructure may also indicate intent to expand their infrastructure footprint to other countries in Latin America and Africa.

    To achieve its goals, the actor must meet four requirements: have access to the National Financial System Network (RSFN) through an entity that already has this access; access to mTLS credentials that allow sending authenticated payloads with transactional orders to Pix or STR; access to several accounts in the targeted organizations' Active Directory and cloud environments; and possess an understanding of an organization's transfer processing procedures, network controls, fintech integrations, and anti-fraud systems.

    The actor has been observed using various tactics to gain initial access to its targets. These tactics include password spraying and voice calls impersonating IT support teams to persuade targets to install Remote Monitoring and Management (RMM) tools such as AnyDesk. In one case highlighted by Axur in November 2025, the actor masqueraded as an IT support personnel over a WhatsApp conversation and guided the victim to install a PowerShell reconnaissance script under the pretext of updating a corporate application.

    Alternatively, the actor has targeted vulnerable JBoss AS servers to deploy web shells, which are then used to deliver additional tooling, including Chisel and other proxy utilities, for follow-on exploitation. The actor's primary targets are organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto.

    The Breeze Comet actor's persistence mechanisms have evolved from dropping commercial RMM tools in 2024 to deploying malicious Kubernetes pods a year later and stealing cloud secrets by exfiltrating them to public-facing notepad websites. Since then, the actor has also been observed making use of multiple custom backdoors as a redundant access method and expanding their foothold.

    Some of the other notable tactics used by the actor include using compromised Brazilian small government websites to stage RMM tools, infostealers dressed up as legitimate tax or receipt documents, and backdoors like XWorm. These tactics are used as C2 endpoints to bypass reputation filters and avoid detection. A similar modus operandi has been replicated across Nigeria, Paraguay, Ghana, and Venezuela, indicating a growing targeting focus.

    Connecting rogue hardware devices directly into retail store networks as a means to establish direct footholds and then move laterally to internal systems, followed by downloading the Netcat utility and custom scripts to retrieve post-exploitation frameworks. Using Impacket, ADRecon, and ADVipscan, and the custom LDAP brute-forcing utility REALBREEZE to conduct internal reconnaissance and escalate privileges by targeting development and cloud environments.

    The actor has also been observed moving laterally by initiating unauthorized Remote Desktop Protocol (RDP) sessions and executing commands via SMB network file shares. This step also involves the deployment of COBALTSPIN, a Rust-based routing malware that operates as a network tunneler to communicate with and maintain persistent network access to financial API infrastructure.

    "By establishing a reverse SOCKS5 proxy over a WebSocket connection, COBALTSPIN routes network traffic securely back and forth between the C2 and internal targets, enabling lateral movement directly through boundary firewalls without requiring built-in persistence mechanisms that might trigger detection," Google said.

    The Breeze Comet actor's persistence mechanisms have evolved from dropping commercial RMM tools in 2024 to deploying malicious Kubernetes pods a year later and stealing cloud secrets by exfiltrating them to public-facing notepad websites. Since then, the actor has also been observed making use of multiple custom backdoors as a redundant access method and expanding their foothold.

    The actor has been observed using LIGHTPAINT, a Java-based backdoor that's used to install the legitimate SoftEther VPN and configure it for automated persistence. MILDFROST, a passive Java JAR backdoor that's used to establish covert DNS tunnels. KICKPLATE, a Nim-based backdoor that impersonates Windows Update Health Tools and is used to deliver secondary payloads and runs commands to control SOCKS5 tunnelers. BOATBEAM, a Golang-based backdoor that initiates a fake IIS HTTPS server on port 443.

    To make sure these persistence mechanisms are not detected and removed, the actor executes PowerShell commands to disable Windows Defender's real-time monitoring on the compromised hosts. In the final stage, COBALTSPIN and compromised privileged accounts are used to access core financial applications and execute hundreds of fraudulent transactions. Once complete, event logs are cleared to minimize the forensic footprint and conceal any API interactions with financial software and payment systems.

    Any directory created during the course of the intrusion is also deleted. The presence of verbose explanatory comments and standardized execution headers indicates the use of a large language model (LLM) to compress the malware development lifecycle. A previous analysis from Trend Micro in May 2026 also found some scripts to include "descriptions of self-reasoning and autonomous decision-making processes."

    "While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, Breeze Comet's campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region," Google said.

    "This transition from opportunistic retail banking fraud to direct intrusions into the core financial switch and instant payment infrastructure is notable not just for this shift in targeting, but also the capabilities of the threat actor. As threat groups increasingly leverage LLMs to streamline routine tradecraft, defenders must anticipate shorter adversary turnaround times and heightened pressure on interconnected financial ecosystems."



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Breeze-Comet-A-Sophisticated-Malware-Actor-Exploiting-Vulnerabilities-in-Brazilian-Payment-Systems-ehn.shtml

  • https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html


  • Published: Tue Sep 1 14:29:45 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us