As cited
Copy frozen at (site build).
threat intel
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Google Threat Intelligence Group tracks BREEZE COMET, a financially motivated Brazilian threat actor active since 2024 that targets financial services, retail, and eCommerce organizations to conduct fraudulent transfers through banking software and payment systems. The group has evolved to use custom malware written in Rust, Nim, Go, and Java, compromised Brazilian government websites for staging and command and control, and generative artificial intelligence (AI) (AI) to accelerate script development and operational speed. BREEZE COMET maintains persistence through multiple backdoors, disables endpoint defenses, and has executed at least one heist totaling tens of thousands of USD.
Why it matters: Banks, fintech companies, payment processors, and retailers in Brazil and potentially Latin America and Africa face direct intrusion risk to core financial infrastructure and instant payment systems; practitioners should implement network segmentation, credential hardening, deep packet inspection on egress traffic, and block unauthorized remote monitoring and management tools to defend against this active and maturing threat.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Google Threat Intelligence Group tracks BREEZE COMET, a financially motivated Brazilian threat actor active since 2024 that targets financial services, retail, and eCommerce organizations to conduct fraudulent transfers through banking software and payment systems. The group has evolved to use custom malware written in Rust, Nim, Go, and Java, compromised Brazilian government websites for staging and command and control, and generative artificial intelligence (AI) (AI) to accelerate script development and operational speed. BREEZE COMET maintains persistence through multiple backdoors, disables endpoint defenses, and has executed at least one heist totaling tens of thousands of USD.
Why it matters: Banks, fintech companies, payment processors, and retailers in Brazil and potentially Latin America and Africa face direct intrusion risk to core financial infrastructure and instant payment systems; practitioners should implement network segmentation, credential hardening, deep packet inspection on egress traffic, and block unauthorized remote monitoring and management tools to defend against this active and maturing threat.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Google Threat Intelligence Group tracks BREEZE COMET, a financially motivated Brazilian threat actor active since 2024 that targets financial services, retail, and eCommerce organizations to conduct fraudulent transfers through banking software and payment systems. The group has evolved to use custom malware written in Rust, Nim, Go, and Java, compromised Brazilian government websites for staging and command and control, and generative artificial intelligence (AI) (AI) to accelerate script development and operational speed. BREEZE COMET maintains persistence through multiple backdoors, disables endpoint defenses, and has executed at least one heist totaling tens of thousands of USD.
Why it matters: Banks, fintech companies, payment processors, and retailers in Brazil and potentially Latin America and Africa face direct intrusion risk to core financial infrastructure and instant payment systems; practitioners should implement network segmentation, credential hardening, deep packet inspection on egress traffic, and block unauthorized remote monitoring and management tools to defend against this active and maturing threat.
- Source published
- First seen by Cybersecurity Tracker