Financially Motivated Threat Actor BREEZE COMET Targets Brazil
BREEZE COMET is a financially motivated threat actor conducting intrusions against Brazilian financial organizations to execute fraudulent transactions via payment systems such as Pix, STR, and Boleto. The group employs a custom multi-language malware suite for persistence, lateral movement, and C2, and abuses compromised government websites for malware staging. BREEZE COMET uses LLMs to accelerate development of reconnaissance and deployment scripts, and has expanded targeting to government domains in Nigeria, Paraguay, Ghana, and Venezuela.
- domaindontpad[.]comPaste site used by BREEZE COMET for data exfiltration of cloud secrets and stolen credentials.
- filenamea.exeExecutable payload staged on compromised government domains.
- filenameattvpn.vipVPN tooling package staged on compromised Nigerian government domain.
- filenameattvpn.zipArchive containing VPN tooling package staged on compromised government domains.
- filenameCOAF-POLICIAFEDERAL.exeMalware filename disguised as a federal police document, dropped from compromised government staging domains.
- filenameComprovanteBBpix.exeMalware filename disguised as a Pix payment confirmation, dropped from compromised government staging domains.
- filenameComprovantePDF.exeMalware filename disguised as a payment receipt or tax document, delivered from compromised government websites during initial access.
- filenamecxv.exeExecutable payload staged on compromised government domains.
- filenamej.jarJava JAR payload staged on compromised government domains, likely MILDFROST or LIGHTPAINT.
- filenamenotepadd.exeExecutable payload staged on compromised government domains.
- filenamer.exeExecutable payload staged on compromised government domains.
- filenamer.zipArchive payload staged on compromised government domains.
- filenames.exeExecutable payload staged on compromised government domains.
- filenameSoftEther.exeLegitimate VPN client deployed by LIGHTPAINT backdoor for persistent access, staged on compromised government domains.
- filenames.zipArchive payload staged on compromised government domains.
- filenametes.exeExecutable payload staged on compromised government domains.
- filenameti.zipArchive containing BREEZE COMET tooling, staged on compromised government domains.
- urlhxxp://credeb[.]gov[.]gn/r[.]zipCompromised Ghanaian government domain hosting archive payload, indicating African expansion.
- urlhxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/notepadd[.]exeCompromised municipal government domain hosting executable payload.
- urlhxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/tes[.]exeCompromised municipal government domain hosting executable payload.
- urlhxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/ti[.]zipCompromised municipal government domain hosting archive containing tooling for BREEZE COMET operations.
- urlhxxps://cmgovernadorluizrocha[.]ma[.]gov[.]br/Comprovantepdf[.]exeCompromised Brazilian state government domain staging malware disguised as a receipt document.
- urlhxxps://conseg[.]ssp[.]go[.]gov[.]br/COAF-POLICIAFEDERAL[.]exeCompromised government domain hosting malware disguised as a federal police document.
- urlhxxps://conseg[.]ssp[.]go[.]gov[.]br/ComprovanteBBpix[.]exeCompromised government domain hosting malware disguised as a Pix payment confirmation document.
- urlhxxps://jmcov[.]gov[.]py/cxv[.]exeCompromised Paraguayan government domain staging executable payload.
- urlhxxps://minacu[.]go[.]gov[.]br/ComprovantePDF[.]exeCompromised municipal government domain staging malware disguised as a receipt document.
- urlhxxps://procon[.]go[.]gov[.]br/ComprovantePDF[.]exeCompromised Brazilian government domain used to stage malware disguised as a receipt or tax document.
- urlhxxps://servicos[.]salto[.]sp[.]gov[.]br/j[.]jarCompromised municipal government domain hosting Java JAR payload, likely MILDFROST or LIGHTPAINT backdoor.
- urlhxxps://sit[.]baer[.]gob[.]ve/r[.]exeCompromised Venezuelan government domain staging executable payload, indicating expansion into South American targets.
- urlhxxps://suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/1[.]exeCompromised municipal government domain hosting executable payload.
- urlhxxps://suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/attvpn[.]zipCompromised municipal government domain staging VPN tooling package for BREEZE COMET operations.
- urlhxxps://tisup[.]camaratunapolis[.]sc[.]gov[.]br/SoftEther[.]exeCompromised municipal government domain hosting SoftEther VPN client used by LIGHTPAINT backdoor for persistence.
- urlhxxp://suporte[.]ourinhos[.]sp[.]gov[.]br:443/files/s[.]exeCompromised municipal government domain hosting executable payload on port 443.
- urlhxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/a[.]exeCompromised municipal government domain hosting executable payload.
- urlhxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/s[.]zipCompromised municipal government domain hosting archive payload.
- urlhxxps://www[.]mrtb[.]gov[.]ng/apps/attvpn[.]vipCompromised Nigerian government domain staging VPN tooling, indicating expansion of BREEZE COMET infrastructure beyond Brazil.
Detection / Hunteropenrouter
What Happened
A criminal group called BREEZE COMET has been breaking into Brazilian banks, payment processors, and retailers since 2024 to steal money by manipulating payment systems. They trick employees into installing malicious software, sometimes by pretending to be IT support on the phone, and they also hack into legitimate government websites to hide their activities. The group uses a collection of custom tools to move through victim networks, stay hidden, and eventually send fraudulent payment instructions. They are also using artificial intelligence to write their attack scripts faster. Organizations in the financial technology sector, especially in Brazil and potentially other countries in Latin America and Africa, should review their security controls, train staff on social engineering, and monitor for the indicators described in this report.
Key Takeaways
- BREEZE COMET is a financially motivated threat actor targeting Brazilian financial infrastructure including Pix, STR, and Boleto payment systems to conduct fraudulent transfers.
- The group uses a multi-language custom malware suite: REALBREEZE (LDAP brute-forcer), COBALTSPIN (Rust SOCKS5 tunneler), LIGHTPAINT (Java VPN backdoor), MILDFROST (Java DNS tunnel backdoor), KICKPLATE (Nim backdoor), and BOATBEAM (Go fake IIS backdoor).
- BREEZE COMET compromises trusted Brazilian government websites to stage malware and serve as C2 endpoints, bypassing domain reputation filters.
- The threat actor uses LLMs to generate reconnaissance and deployment scripts, compressing development cycles and lowering technical barriers.
- Operations have expanded beyond Brazil to Nigeria, Paraguay, Ghana, and Venezuela, indicating growing targeting focus in Latin America and Africa.
Affected Systems
- Brazilian financial systems (Pix, STR, Boleto)
- Active Directory environments
- Cloud and Kubernetes environments
- JBoss AS servers
- Windows endpoints
- CI/CD pipeline infrastructure
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: BREEZE COMET uses password spraying, voice phishing impersonating IT support, compromised government websites to stage malware, rogue hardware devices on retail networks, and JBoss AS server vulnerabilities.
- Execution: RMM tools (AnyDesk), XWORM backdoor, and infostealers disguised as tax documents are deployed; reconnaissance utilities (Impacket, ADRecon) are downloaded from GitHub and executed in memory via PowerShell.
- Privilege Escalation: Custom REALBREEZE LDAP brute-forcer compromises Active Directory; CI/CD environments are mined for hardcoded credentials, API keys, and cloud tokens; custom scripts search for mTLS credentials using terms like boleto, cnab, remessa, webhook.*pix.
- Lateral Movement: Hijacked service accounts used for RDP sessions and SMB file shares; COBALTSPIN Rust-based SOCKS5 tunneler routes traffic through boundary firewalls via WebSocket reverse proxy.
- Persistence: Multiple redundant backdoors deployed including LIGHTPAINT (VPN persistence), MILDFROST (DNS tunnel C2), KICKPLATE (scheduled tasks and startup shortcuts), BOATBEAM (fake IIS server); malicious Kubernetes pods used for cloud persistence; Windows Defender disabled via PowerShell.
- Exfiltration and Impact: Cloud secrets exfiltrated to dontpad.com; within 24-48 hours of accessing core financial applications, hundreds of fraudulent transactions executed via Pix, STR, or Boleto APIs; event logs and created directories deleted to cover tracks.
Detection Availability
- YARA Rules: Yes
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: Yes
- Platforms: Google SecOps, Google Threat Intelligence Group YARA rules
YARA rules for REALBREEZE, COBALTSPIN, BOATBEAM, and MILDFROST are provided in the blog post. Google SecOps detection rules are available under the 'Mandiant Hunting Rules' rule pack with rule names including 'Network DNS Connections To Pastebin', 'Powershell Downloadstring Method With Suspicious Arguments', and 'Powershell Loading Net Assembly'.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | BREEZE COMET executes reconnaissance tools in memory via PowerShell and disables Windows Defender real-time monitoring, which may reduce EDR telemetry. However, process creation events, scheduled task creation, and service modifications should still be visible if EDR is functioning before Defender is disabled. |
| Network Visibility | Medium | COBALTSPIN uses WebSocket-based SOCKS5 tunneling over standard ports, and BOATBEAM masquerades as IIS on port 443, making C2 traffic blend with legitimate web traffic. DNS tunneling via MILDFROST may be detectable with DNS analytics. Compromised .gov domains may bypass domain reputation filters. |
| Detection Difficulty | Hard | The threat actor uses multiple evasion techniques including in-memory PowerShell execution, disabling Defender, masquerading as legitimate services (IIS, Windows Update Health Tools), DNS tunneling, and compromised trusted government domains for staging. Multi-language backdoors provide redundant access, making full eradication difficult. The use of standard protocols (RDP, SMB, HTTPS) for lateral movement blends with legitimate activity. |
Required Log Sources
- Windows Security Event ID 4624 (authentication events)
- Windows Security Event ID 4672 (privileged logon)
- PowerShell Script Block Logging (Event ID 4104)
- Windows Task Scheduler operational logs
- Windows System Event ID 7045 (service installation)
- DNS query logs
- Proxy/egress firewall logs with SSL/TLS decryption
- Kubernetes audit logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for PowerShell processes loading .NET assemblies in memory, which may indicate in-memory execution of reconnaissance tools downloaded from GitHub repositories. | PowerShell Script Block Logging (Event ID 4104), Sysmon Event ID 1 with command line, EDR process telemetry | Execution | Medium - legitimate administrative scripts may load assemblies; correlate with network connections to GitHub or known reconnaissance tool signatures. |
| Consider hunting for processes making outbound DNS queries to delegated subdomains with high frequency or unusual query patterns, which may indicate MILDFROST DNS tunneling C2 activity. | DNS query logs, passive DNS, network flow data | Command and Control | Medium - legitimate applications may use frequent DNS queries; look for patterns consistent with tunneling protocols and unusually long subdomain labels. |
| Consider hunting for scheduled tasks created and configured to run as SYSTEM, particularly those with suspicious command lines or executing from non-standard paths, as KICKPLATE uses this technique for persistence. | Windows Task Scheduler operational logs, EDR scheduled task creation events, Sysmon Event ID 1 | Persistence | Low to Medium - legitimate administrative tasks may run as SYSTEM; focus on tasks created outside of standard deployment tools and those with unusual binary paths. |
| Consider hunting for file searches or script executions referencing financial system terms such as boleto, cnab, remessa, webhook.*pix, or instant.*payment, which may indicate BREEZE COMET credential harvesting for mTLS authentication material. | PowerShell Script Block Logging, file access auditing, EDR file read events, command line logging | Credential Access | Low - these terms are specific to Brazilian financial systems and are unlikely to appear in routine administrative scripts outside of financial application contexts. |
| Consider hunting for inbound Windows Defender Firewall rule additions that allow all traffic from VPN manager processes, followed by clearing of Windows Networking Vpn Plugin Platform event logs, which may indicate LIGHTPAINT deployment. | Windows Firewall event logs, Windows Networking Vpn Plugin Platform logs, EDR registry modification events | Persistence | Low - programmatic firewall rule creation allowing all traffic from a VPN client is unusual; log clearing of VPN platform events is a strong indicator of malicious activity. |
Control Gaps
- Domain reputation filters and .gov TLD allowlists will not detect malware staged on compromised government domains.
- Standard egress filtering may not detect COBALTSPIN WebSocket-based SOCKS5 tunneling over common ports.
- BOATBEAM's fake IIS server on port 443 may not be distinguished from legitimate web server traffic without deep packet inspection.
- MILDFROST DNS tunneling may bypass standard network monitoring if DNS traffic is not analyzed for tunneling patterns.
- Disabling Windows Defender real-time monitoring via PowerShell may go undetected if PowerShell command logging is not enforced.
- Rogue hardware devices connected to retail store networks may bypass network access controls if 802.1X NAC is not deployed.
Key Behavioral Indicators
- PowerShell execution of Set-MpPreference to disable real-time monitoring
- Scheduled tasks created to run as SYSTEM from non-standard binary paths
- Processes impersonating Windows Update Health Tools executing from atypical locations
- Java processes (JVM) initiating DNS queries with tunneling patterns consistent with MILDFROST
- Inbound Windows Defender Firewall rules allowing all traffic from VPN manager processes
- Clearing of Windows Networking Vpn Plugin Platform event logs
- Processes listening on port 443 that are not legitimate IIS worker processes (w3wp.exe)
- Service account credentials used for RDP sessions from atypical source hosts
- File searches or script executions referencing Brazilian financial terms (boleto, cnab, remessa, pix)
- Kubernetes pod creation events from non-administrative service accounts or with privileged container flags
False Positive Assessment
Medium - Several indicators such as PowerShell execution, scheduled task creation, and RDP sessions are common in administrative environments. However, the combination of financial system search terms, Defender disabling, VPN firewall rule manipulation, and DNS tunneling patterns significantly reduces false positive risk when correlated. Compromised government domain URLs are high-confidence indicators but may require validation that the domains are not legitimately accessed by the organization.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider searching endpoint and network logs for the compromised government staging URLs and filenames listed in this report.
- If your organization operates in the Brazilian financial sector, consider auditing Active Directory for accounts with access to RSFN, Pix, STR, or Boleto APIs and verifying that mTLS credentials have not been compromised.
- Consider blocking the compromised government domains and URLs listed in this report at your web proxy or firewall, while validating that legitimate services are not impacted.
- If you have EDR visibility, consider hunting for PowerShell processes executing Set-MpPreference to disable real-time monitoring and for scheduled tasks running as SYSTEM from non-standard paths.
Infrastructure Hardening
- Consider deploying 802.1X Network Access Control on physical switch ports at branch and retail locations to prevent rogue hardware devices from obtaining network access.
- Evaluate whether SSL/TLS decryption and deep packet inspection on outbound web traffic would improve detection of C2 traffic masquerading as legitimate HTTPS, rather than relying on domain reputation or .gov TLD allowlists.
- Consider implementing network segmentation to block lateral SMB and RDP traffic between workstations and servers where such traffic is not required.
- If your organization uses Kubernetes, consider enforcing strict RBAC for service accounts and using admission controllers to block privileged containers.
- Consider implementing egress network policies to block nodes and pods from accessing unauthorized public platforms such as paste sites.
- Evaluate whether a centralized secrets manager with access logging would reduce the risk of plaintext credentials in CI/CD pipelines and code repositories.
User Protection
- Consider enforcing application control to block execution of binaries from user-writable directories such as %APPDATA%, ~/Downloads, and /tmp.
- If applicable, consider enforcing PowerShell Constrained Language Mode, Script Block Logging, and AMSI to detect in-memory execution of reconnaissance scripts.
- Consider auditing software inventory to detect and alert on portable RMM tool execution such as AnyDesk.
- Evaluate whether phishing-resistant MFA is enforced across all external portals including VPNs and SaaS applications.
Security Awareness
- Consider incorporating voice phishing (vishing) awareness into existing security training programs, particularly scenarios involving callers impersonating IT support teams.
- If your organization is in the Brazilian financial sector, consider training staff on the risk of installing RMM tools based on phone instructions from alleged IT support.
- Consider briefing development and CI/CD teams on the risk of hardcoded credentials in pipelines and the importance of using centralized secrets management.
MITRE ATT&CK Mapping
Initial Access
Execution
Persistence
Credential Access
Lateral Movement
Command and Control
Impact
Additional IOCs
- Urls:
hxxps://cmgovernadorluizrocha[.]ma[.]gov[.]br/Comprovantepdf.exe- Compromised Brazilian state government domain staging malware disguised as a receipt document.hxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/ti.zip- Compromised municipal government domain hosting archive containing tooling for BREEZE COMET operations.hxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/notepadd.exe- Compromised municipal government domain hosting executable payload.hxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/tes.exe- Compromised municipal government domain hosting executable payload.hxxps://minacu[.]go[.]gov[.]br/ComprovantePDF.exe- Compromised municipal government domain staging malware disguised as a receipt document.hxxps://suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/1.exe- Compromised municipal government domain hosting executable payload.hxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/s.zip- Compromised municipal government domain hosting archive payload.hxxp://suporte[.]ourinhos[.]sp[.]gov[.]br:443/files/s.exe- Compromised municipal government domain hosting executable payload on port 443.hxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/a.exe- Compromised municipal government domain hosting executable payload.hxxps://servicos[.]salto[.]sp[.]gov[.]br/j.jar- Compromised municipal government domain hosting Java JAR payload, likely MILDFROST or LIGHTPAINT backdoor.hxxp://credeb[.]gov[.]gn/r.zip- Compromised Ghanaian government domain hosting archive payload, indicating African expansion.
- File Paths:
COAF-POLICIAFEDERAL.exe- Malware filename disguised as a federal police document, dropped from compromised government staging domains.ComprovanteBBpix.exe- Malware filename disguised as a Pix payment confirmation, dropped from compromised government staging domains.attvpn.zip- Archive containing VPN tooling package staged on compromised government domains.SoftEther.exe- Legitimate VPN client deployed by LIGHTPAINT backdoor for persistent access, staged on compromised government domains.ti.zip- Archive containing BREEZE COMET tooling, staged on compromised government domains.notepadd.exe- Executable payload staged on compromised government domains.tes.exe- Executable payload staged on compromised government domains.s.zip- Archive payload staged on compromised government domains.s.exe- Executable payload staged on compromised government domains.a.exe- Executable payload staged on compromised government domains.j.jar- Java JAR payload staged on compromised government domains, likely MILDFROST or LIGHTPAINT.r.zip- Archive payload staged on compromised government domains.r.exe- Executable payload staged on compromised government domains.cxv.exe- Executable payload staged on compromised government domains.attvpn.vip- VPN tooling package staged on compromised Nigerian government domain.
- Command Lines:
- Purpose: Disable Windows Defender real-time monitoring on compromised hosts to ensure malware suite remains operational. | Tools:
PowerShell,Set-MpPreference| Stage: Defense Evasion |Set-MpPreference -DisableRealtimeMonitoring - Purpose: Create scheduled tasks running as SYSTEM for host-level persistence alongside KICKPLATE backdoor. | Tools:
schtasks.exe| Stage: Persistence |schtasks.exe /create /tn <taskname> /tr
- Purpose: Disable Windows Defender real-time monitoring on compromised hosts to ensure malware suite remains operational. | Tools: