Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources THREAT INTELLIGENCE APPLICATION SECURITY VULNERABILITIES & THREATS CYBERATTACKS & DATA BREACHES NEWS Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America. 'Breeze Comet' Tears Into Brazilian & Global Financial Systems Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket. Nate Nelson,Contributing Writer September 3, 2026 6 Min Read SOURCE: GWENGOAT VIA GETTY IMAGES A cybercrime group is infiltrating Brazilian financial systems to abuse payment infrastructure and send itself illegal transactions. Most hackers want money. Most of the time, they get it in some roundabout kind of way. They might convince vulnerable individuals to invest in fake currency exchanges. They might lock up all of a company's files, then hold them for ransom. "Breeze Comet," formerly known as UNC5669, goes straight to the source. It targets financial institutions: financial services, fintech, retail, point-of-sale (PoS), and e-commerce companies, plus government organizations and banks. Using custom malware and creative infiltration tactics, it pries into the systems that Brazilian financial organizations use to perform transactions and simply initiates payments to itself, for up to tens of thousands of US dollars at a time, according to new research from Google Threat Intelligence Group (GTIG) and Mandiant. Worse, experts warn that this same model might work in many other countries, too. Related:Interpol's Jackal IV Disrupts West African Crime Infrastructure Getting Into Brazilian Corporate Networks The earliest Breeze Comet attacks observed by Mandiant, in 2024, began with standard fare intrusion techniques: password spraying, and vishing calls impersonating IT support desks, with the goal of installing remote monitoring and management (RMM) software inside of targeted organizations. These tactics concealed just how sophisticated and motivated it was. In 2025, researchers at threat intelligence firm Axur discovered that the hackers were trying to recruit insiders at targeted companies. In other cases, they would connect their own hardware directly into retail store networks to establish initial access points. "Once connected to physical ports, the rogue devices successfully requested and were assigned internal IP addresses by the organizations' own Dynamic Host Configuration Protocol (DHCP) servers," GTIG says in a statement to Dark Reading. "A lack of network segmentation allowed the threat actors to conduct reconnaissance and expand their access to targeted organizations’ corporate networks from this initial foothold." GTIG advises that organizations implement some quick fixes to prevent this kind of thing happening to them. "Deploy 802.1X Network Access Control (NAC) across physical Ethernet switch ports at branch/retail locations to prevent unauthorized hardware devices from obtaining an internet protocol (IP) address or communicating on internal subnets," GTIG says, adding that it's also a good idea to disable unused network switch ports and physically restrict access to networking closets and public-facing jacks. Related:'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft The Brazilian group seems to have landed on its most effective intrusion strategy midway through last year. It identified small, insufficiently secure Brazilian government websites, staged its malware on those sites, and leveraged their trusted domains in follow-on social engineering attacks against its actual targets. Worryingly, it has also been trying to replicate this winning formula in other regions, hacking municipal websites in countries like Nigeria, Paraguay, Ghana, and Venezuela. Additionally, Mandiant and GTIG researchers observed evidence that Breeze Comet is using generative AI to develop its malware, "may further increase the scale, speed, and sophistication of their operations in the future," according to the report. How Breeze Comet Steals Cash After the point of intrusion, Breeze Comet uses an arsenal of custom malware designed to achieve privilege escalation, lateral movement, and persistence. Among them, "RealBreeze" brute forces Lightweight Directory Access Protocol (LDAP) directory servers, "LightPaint" installs a legitimate VPN to establish persistence, and "KickPlate" impersonates Windows Update Health Tools while modifying Windows services, manipulating registry startup keys, facilitating the installation of supplementary payloads. Related:SE Asian Cybercriminal Syndicates Become a Global Power The group's most interesting malware, perhaps, is "CobaltSpin," which weasels through strictly segmented and firewalled financial networks by establishing a network tunnel from an internal, compromised machine out to its command-and-control (C2) infrastructure. The goal, ultimately, is to reach the financial applications that organizations use to make payments — in Brazil's case, systems like Pix, Boleto, and the Reserves Transfer System (STR). "This group are experts in Brazil's instant payment system — they know it inside and out," marvels Zach Edwards, staff threat researcher at Axur parent company Infoblox. "It understands that every single deployment of Pix is going to be slightly different. So once you compromise an organization that may have access to Pix, you're going to need to figure out their authorization processes, their fraud and abuse processes, how you're going to try and submit fraudulent orders in a giant burst, or dripping them out over time. So they study an organization, to figure out how they could potentially get those transactions to execute without triggering their fraud and abuse systems." At that point, it's time to cash out. In one case observed by researchers, Breeze Comet executed hundreds of fraudulent transactions within 24 to 48 hours of obtaining access to a targeted payment system, and stole an amount of Brazilian Real equivalent to tens of thousands of dollars. Edwards advises that organizations watch out for this activity by identifying the tunnels and RMMs Breeze Comet uses to perform internal network commands. "If you're a business, and you don't have an authorized use for RMM or various other sorts of remote monitoring technologies or remote customer support, ban them and block those domains using them." Besides that, he suggests that scrutiny be applied to manager approval workflows. "Auditing that process you have before a transaction can be verified, and ensuring that it has the right controls that you expect in your organization," he says. "Maybe that's a two-factor authentication (2FA), maybe that's a passkey, whatever it may be — ensuring that an API call can't trigger these transactions and there is some sort of secondary process involved." Brazil's Exceptional Cybercrime Scene Breeze Comet can be viewed as a direct outgrowth of socioeconomic forces dating back to the 1990s, if not earlier. "In the 90s, Brazil suffered from hyperinflation," explains Tom Kellermann, vice president of AI security and threat research at TrendAI, which also observed Breeze Comet activity earlier this year. "As a result of hyperinflation, they started teaching kids how to use computers. Computer science was mandatory in schools," as the crisis heightened a perceived need for modernization. He adds that "This was coupled with the fact that they were the first country in Latin America to move to electronic finance in 1995. So money became digital, but the kids didn't get jobs. So you had this very robust organized cybercrime community that began to develop as early as 1998 in Brazil, targeting the banks, because money was digital. And then following suit, many Latin American banks, Spanish speaking banks, were dealing with the barrage of attacks from very organized cybercrime gangs that are affiliated with some of the major drug gangs and prison gangs of Brazil." Today, Kellermann says, Brazilian threat actors pose an equal or greater threat than their counterparts in Iran, North Korea, and other notorious hubs of international cybercrime. And Breeze Comet is a level beyond even other Brazilian groups. "They're the most significant threat actor in Latin America," Kellermann argues. And, he warns, "The way that they've been targeting the financial institutions — that model can be replicated across other sectors." Read more about: DR Global Latin America About the Author Nate Nelson Contributing Writer Nate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media. He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify. He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars How to L