Breeze Comet Threat Group Targets Global Financial Infrastructure
The Brazilian cybercrime syndicate leverages custom malware to manipulate instant payment systems and compromise government websites worldwide.
A sophisticated Brazilian threat group known as Breeze Comet is infiltrating financial institutions and government organizations to manipulate payment infrastructure and execute fraudulent transactions. The group, formerly tracked as UNC5669, has evolved beyond regional crime to target a global array of fintechs, retail point-of-sale systems, and e-commerce platforms.
To achieve its goals, Breeze Comet employs a specialized arsenal of custom malware designed for deep network penetration. The group utilizes 'RealBreeze' for LDAP brute forcing and 'LightPaint' to maintain VPN persistence. They further secure their foothold using 'KickPlate' for Windows service manipulation and 'CobaltSpin' for network tunneling, allowing them to bypass security layers and initiate direct transfers to their own accounts.
The Evolution of Brazilian Cybercrime
This surge in activity is rooted in Brazil's unique economic history. Starting in the 1990s, hyperinflation and a rapid transition to electronic finance created a fertile environment for technically skilled individuals to pivot toward banking fraud. Breeze Comet represents the modern apex of this tradition, demonstrating a level of sophistication and operational security that exceeds previous Brazilian threat actors.
"This group are experts in Brazil's instant payment system — they know it inside and out," said Zach Edwards, a staff threat researcher at Infoblox. Tom Kellermann, VP of AI security and threat research at TrendAI, described the group as "the most significant threat actor in Latin America."
Systemic Risks to Global Payments
The group's ability to compromise segmented financial networks poses a systemic risk to critical payment rails. Specifically, Breeze Comet targets high-velocity systems including Pix, Boleto, and the STR (Sistema de Transferência de Reservas). By manipulating these instant payment mechanisms, the group can move funds rapidly before traditional fraud detection systems can intervene.
Furthermore, the threat has expanded geographically. Breeze Comet has successfully compromised municipal government websites in Nigeria, Paraguay, Ghana, and Venezuela. These hijacked sites are used as command-and-control (C2) hubs and as platforms for social engineering, suggesting the group is replicating its Brazilian success in other emerging markets.
Future Outlook
Security researchers are now monitoring how Breeze Comet continues to adapt its social engineering tactics to gain internal system access. While the group has already proven its ability to weaponize government infrastructure for financial gain, the primary concern for the industry remains the vulnerability of instant payment systems. As more nations adopt real-time settlement rails, the blueprint established by Breeze Comet provides a dangerous roadmap for other financially motivated actors to follow.