hacker-news · Crawled Sep 2, 2026

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

1 IoCs 1 Malware
Read original article ↗

AI Summary

Breeze Comet, a financially motivated threat actor active since 2023 and previously tracked as UNC5669, has targeted Brazilian financial, retail, and e-commerce organizations to conduct fraudulent transactions via payment systems like Pix, STR, and Boleto. The group gains initial access through password spraying, social engineering via WhatsApp, and exploitation of vulnerable JBoss AS servers to deploy web shells. They use a suite of custom backdoors such as LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, along with tools like COBALTSPIN for lateral movement and SOCKS5 tunneling, to maintain persistence and execute hundreds of fraudulent transactions. The actor leverages compromised government websites for C2 infrastructure, disables Windows Defender via PowerShell, and uses LLMs to accelerate malware development, indicating a shift toward more sophisticated, infrastructure-level financial attacks.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 1 extracted

Type Value Detail
Domain dontpad[.]com Details →

MITRE ATT&CK TTPs 23 techniques