BREEZE COMET is a financially motivated threat actor conducting intrusions against Brazilian financial organizations to execute fraudulent transactions via payment systems such as Pix, STR, and Boleto. The group employs a custom multi-language malware suite for persistence, lateral movement, and C2, and abuses compromised government websites for malware staging. BREEZE COMET uses LLMs to accelerate development of reconnaissance and deployment scripts, and has expanded targeting to government domains in Nigeria, Paraguay, Ghana, and Venezuela.
XWorm
2 posts
Financially Motivated Threat Actor BREEZE COMET Targets Brazil The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications Aeternum is a C++ botnet loader that migrates C2 infrastructure to the public Polygon blockchain, using smart contracts to store encrypted and plaintext commands. Infected devices query public RPC endpoints to retrieve on-chain instructions, decrypt them using a flawed PBKDF2HMAC/AES-GCM routine, and execute payloads including XWorm RAT, XMRig miner, and cryptocurrency wallet stealers. The decentralized architecture complicates takedown efforts and provides resilient, low-cost C2 infrastructure.