Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
AI Summary
Breeze Comet, a financially motivated threat actor active since 2023 and previously tracked as UNC5669, has targeted Brazilian financial, retail, and e-commerce organizations to conduct fraudulent transactions via payment systems like Pix, STR, and Boleto. The group gains initial access through password spraying, social engineering via WhatsApp, and exploitation of vulnerable JBoss AS servers to deploy web shells. They use a suite of custom backdoors such as LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, along with tools like COBALTSPIN for lateral movement and SOCKS5 tunneling, to maintain persistence and execute hundreds of fraudulent transactions. The actor leverages compromised government websites for C2 infrastructure, disables Windows Defender via PowerShell, and uses LLMs to accelerate malware development, indicating a shift toward more sophisticated, infrastructure-level financial attacks.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | dontpad[.]com | Details → |