BREEZE COMET is a financially motivated threat actor conducting intrusions against Brazilian financial organizations to execute fraudulent transactions via payment systems such as Pix, STR, and Boleto. The group employs a custom multi-language malware suite for persistence, lateral movement, and C2, and abuses compromised government websites for malware staging. BREEZE COMET uses LLMs to accelerate development of reconnaissance and deployment scripts, and has expanded targeting to government domains in Nigeria, Paraguay, Ghana, and Venezuela.
Brazilian financial fraud
1 post
Financially Motivated Threat Actor BREEZE COMET Targets Brazil