Breeze Comet Exploits Brazilian Payment Systems for Fraud
A financially motivated threat actor known as Breeze Comet has been targeting Brazilian financial institutions and e-commerce platforms since 2024. The group specializes in manipulating local payment systems to execute unauthorized transactions.
TL;DR
- Breeze Comet (UNC5669) has targeted Brazilian finance and retail sectors since 2024.
- The group manipulates local banking software to initiate fraudulent fund transfers.
- Attacks focus on exploiting weaknesses in Brazil's payment infrastructure.
- Google Threat Intelligence and Mandiant have tracked the campaign.
- Organizations should review access controls and monitor for unusual transaction patterns.
Cybercriminals continue to evolve their tactics in pursuit of financial gain, with a new threat actor named Breeze Comet now making headlines for its activities in Brazil. Active since 2024, this group has focused on compromising financial services, retail, and e-commerce organizations by directly manipulating local payment infrastructures.
According to findings from Google Threat Intelligence Group (GTIG) and Mandiant, Breeze Comet demonstrates a high level of specialization in attacking Brazilian banking software and transaction systems. These capabilities allow them to carry out hundreds of unauthorized fund transfers without triggering immediate detection mechanisms.
Attack Strategy and Targets
- Breeze Comet primarily targets Brazilian financial institutions, retailers, and online commerce platforms.
- The group leverages compromised credentials and internal system access to manipulate core banking applications.
- Their operations involve real-time manipulation of transaction workflows within localized payment gateways.
- Multiple victims have reported significant financial losses due to unauthorized fund movements.
Defensive Recommendations
- Implement strict access control policies around critical financial transaction systems.
- Monitor for anomalous behavior in user sessions involving sensitive payment functions.
- Regularly audit third-party integrations that connect to core banking or payment processing modules.
- Deploy behavioral analytics tools capable of detecting abnormal transaction initiation patterns.
- Coordinate with local cybersecurity authorities and intelligence firms for updated threat indicators.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.