A financially motivated hacking group has successfully stolen tens of thousands of U.S. dollars from Brazilian financial services, retail, and e-commerce companies by manipulating payment systems and executing hundreds of fraudulent transactions, according to a new report from Google Threat Intelligence Group and Mandiant. The threat actor, dubbed Breeze Comet, has been active since 2024 and specializes in compromising organizations with direct access to Brazil's banking software, APIs, and payment networks including Pix, STR, and Boleto. The adversary's campaigns mark a shift from opportunistic retail fraud to intrusions targeting core financial infrastructure across Latin America and potentially Africa.
The hackers gain initial entry through password spraying attacks and voice calls where they impersonate IT support staff to trick victims into installing remote monitoring tools like AnyDesk. In one November 2025 incident documented by Axur, attackers masqueraded as corporate IT personnel via WhatsApp and walked a victim through installing a PowerShell reconnaissance script disguised as an application update. The group also exploits vulnerable JBoss AS servers to plant web shells, which deliver additional tools including Chisel and proxy utilities for deeper network penetration. To carry out their heists, Breeze Comet must obtain four critical assets: access to Brazil's National Financial System Network through a compromised entity, mTLS credentials that authenticate transaction orders to Pix or STR, multiple accounts in targeted organizations' Active Directory and cloud systems, and detailed knowledge of an organization's transfer procedures and anti-fraud defenses. The attackers establish persistence through custom backdoors including LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM, while deploying COBALTSPIN—a Rust-based routing malware that creates a reverse SOCKS5 proxy over WebSocket connections to tunnel network traffic between command-and-control servers and internal payment APIs.
Google's analysis reveals that "Breeze Comet tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command-and-control, and to interact with financial software and payment APIs." The threat actor hijacks small Brazilian government websites to host remote monitoring tools, infostealers disguised as tax documents, and backdoors like XWorm, while using these compromised sites as command servers to evade reputation filters. Similar infrastructure patterns have emerged across Nigeria, Paraguay, Ghana, and Venezuela, signaling expanding geographic ambitions. The report notes that verbose comments and standardized execution headers in the malware "indicates the use of a large language model to compress the malware development lifecycle," with a May 2026 Trend Micro analysis identifying scripts containing "descriptions of self-reasoning and autonomous decision-making processes."
The report warns that Breeze Comet's campaigns represent a notable evolution in Latin American cybercrime, which has historically focused on client-side, high-volume retail fraud rather than direct attacks on financial switching and instant payment infrastructure. According to Google, the transition is significant not only for the shift in targeting but also for the technical capabilities the adversary demonstrates. The authors caution that "as threat groups increasingly leverage LLMs to streamline routine tradecraft, defenders must anticipate shorter adversary turnaround times and heightened pressure on interconnected financial ecosystems." Organizations with access to payment networks face growing risk from adversaries who combine social engineering, custom malware, and infrastructure designed to bypass boundary firewalls without triggering detection mechanisms. Financial institutions across the region will need to shore up defenses against attackers who understand both the technical architecture of payment APIs and the operational procedures that govern legitimate transfers. The professionalization of payment infrastructure attacks could reshape the threat landscape for any organization touching Brazil's financial networks, setting a template that other criminal groups may adapt for their own campaigns.

