PRODIST Content

BREEZE COMET: What the Attacks on the Brazilian Financial System Reveal About the Evolution of Cyber Threats

BREEZE COMET is the name given by the Google Threat Intelligence Group (GTIG) to a financially motivated threat actor that has been attacking Brazilian organizations and seeking access to payment systems, banking software, and APIs to carry out fraudulent transfers. 

The case is notable for the technical knowledge of the financial ecosystem and the increasing sophistication of the attacks.

Mandiant's investigation began in 2024 and involves security breaches observed at organizations in the financial, retail, and e-commerce sectors in Brazil. 

In September 2026, the GTIG published details of the operation and began referring to the cluster previously known as UNC5669 as BREEZE COMET.

More than just another malware campaign, this incident serves as an important warning to banks, fintech companies, payment institutions, and companies that integrate with financial infrastructures: protecting the application or the network perimeter on its own is no longer enough.

These attacks show that credentials, certificates, keys, privileged identities, development environments, cloud infrastructure, and financial communication channels must all be part of a single security strategy.

What is BREEZE COMET, and why is it causing concern in the financial market?

According to GTIG and Mandiant, BREEZE COMET specializes in compromising environments capable of processing transactions through banking software, APIs, and payment systems, including Pix, the Reserve Transfer System (STR), and boleto.

Potential targets include banks, fintech companies, payment processors, retailers, brokerage firms, and banking software providers.

The key difference lies in the depth of commitment required to achieve the ultimate goal.

To carry out fraudulent transfers, the group seeks conditions such as access to the National Financial System Network (RSFN) through an organization connected to the network; mutual Transport Layer Security (mTLS) credentials used for authentication; privileged accounts; persistent access to Active Directory or cloud environments; and knowledge of integrations, internal procedures, and anti-fraud controls.

In other words, the goal is not simply to compromise a workstation. The attacker seeks to gain access to components capable of authorizing or enabling actual financial transactions.

How do BREEZE COMET attacks begin?

There is no single point of entry. In incidents that have been investigated, techniques such as password spraying, social engineering via phone calls, and tricking users into installing legitimate remote monitoring and management tools have been identified.

In other cases, legitimate websites that had previously been compromised were used to host malicious tools and files disguised as seemingly trustworthy documents, such as receipts and tax documents. This strategy can undermine security mechanisms that rely too heavily on domain reputation to classify a connection as trustworthy.

Unauthorized physical devices connected directly to the establishments' networks were also observed, in addition to the exploitation of vulnerabilities on servers.

The diversity of these paths illustrates an important principle: the protection of financial transactions must take into account that the initial compromise may occur far removed from the system that actually processes the transaction.

From the initial compromise to financial credentials: How does the attack unfold?

Once inside the environment, the goal becomes to escalate privileges and understand the victim's infrastructure.

BREEZE COMET was analyzed using publicly available reconnaissance tools and proprietary software to identify accounts, services, servers, and potential paths for lateral movement.

One issue that is particularly relevant to the financial sector is the demand for credentials, certificates, API keys, and access tokens.

The investigation identified searches in continuous integration and continuous delivery (CI/CD) environments, internal files, and environment variables. The goal is to find mTLS credentials and administrative certificates capable of authenticating financial systems.

This behavior illustrates why technical secrets should not be left exposed in code, scripts, configuration files, or inadequately protected variables.

A high-privilege credential can serve as a bridge between a compromise of the IT infrastructure and access to a critical financial operation.

Lateral movement and persistence increase the complexity of the attack

Once established in the market, BREEZE COMET seeks to expand its presence.

Mandiant identified the use of compromised service accounts, Remote Desktop Protocol (RDP) connections, Server Message Block (SMB) shares, scanning tools, and custom tunneling mechanisms.

Among them is COBALTSPIN, malware written in Rust that creates a SOCKS5 reverse proxy over WebSocket, allowing traffic to be routed between the attacker's command-and-control infrastructure and the organization's internal resources.

Several backdoors designed to provide redundant access were also identified, including LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM.

The existence of multiple persistence mechanisms is important because removing just one malicious artifact from the environment does not necessarily mean that the attacker has lost access.

Artificial intelligence is also beginning to accelerate cyberattacks

Another important aspect of the research is the potential use of generative artificial intelligence.

Mandiant found evidence that large language models were used to accelerate the creation of scripts designed for network reconnaissance, credential validation, large-scale deployment, targeted movement within compromised environments, and data extraction.

This case is part of a broader trend. In September 2026, the GTIG reported that it was monitoring the evolution of malicious agents from basic uses of AI to automated workflows and even agents capable of significantly reducing the time required for certain stages of an attack.

This does not mean that AI has replaced attackers' technical expertise. The most immediate impact is on speed and scale.

Activities that previously required manual processing can be partially automated, reducing the time available for detection and response.

cyberattack-on-the-brazilian-financial-system-prodist-technology-solutions-financial-market

BREEZE COMET and Silver Fox: Different Attacks, a Similar Warning

In the same week that BREEZE COMET was announced, Microsoft provided details on another campaign that helps shed light on the current threat landscape.

In this case, fake websites that impersonated legitimate software vendors were used to distribute malicious installers. Once executed, the malware established persistence, attempted to bypass security mechanisms, and communicated with infrastructure controlled by the attackers. 

Microsoft assessed, with moderate confidence, that the activity was consistent with the campaign known as Silver Fox, without attributing it to a state-sponsored actor.

Although these are different operations, there is one common conclusion: the fact that a file, website, application, or user appears legitimate should not be enough to establish trust.

This reality reinforces security strategies based on continuous validation, least privilege, and protection of the most critical assets.

What does the BREEZE COMET case teach us about protecting financial systems?

There is no single control measure capable of preventing every stage of a campaign of this nature.

Mandiant itself recommends a layered approach, including application control, restrictions on unauthorized remote management tools, phishing-resistant multi-factor authentication, network segmentation, Active Directory protection, greater control over Kubernetes and cloud environments, traffic monitoring, and centralized secret management.

For financial institutions, certain points deserve special attention:

  • Credentials and secrets: certificates, private keys, tokens, and technical credentials must have controlled storage, access, and lifecycle management.
  • Privileges: Administrative and service accounts must adhere to the principle of least privilege.
  • Segmentation: Compromising a workstation should not provide a direct path to transactional environments.
  • Traceability: Logs and audit trails are essential for detecting anomalous behavior and reconstructing incidents.
  • Protection of integrations: Systems connected to Pix, STR, RSFN, and other critical infrastructures must be treated as high-risk components.
  • Layered defense: endpoints, identity, networks, applications, APIs, the cloud, and cryptographic assets must function as complementary layers.

Secret management is particularly important. Among the recommendations released by Mandiant is the use of a centralized secret manager with access logging, to avoid storing keys in plain text within the code.

Security must keep pace with evolving threats

BREEZE COMET demonstrates that attacks on the financial market are evolving from frauds targeting exclusively the end user to attempts to directly compromise the infrastructure used to process transactions.

In this scenario, security solutions must also continue to evolve.

PRODIST keeps pace with technological and regulatory changes in the financial market to ensure its solutions remain aligned with the needs of critical environments. This involves technologies related to cryptography, key management and protection, authentication, digital signatures, and integrations with financial systems.

Solutions such as PRODIST STS can be integrated into broader strategies for protecting cryptographic assets, enabling organizations to implement controls tailored to the characteristics of their architecture, including in environments that use HSMs, vaults, and key management services.

Technology, however, is just one layer. Cases such as BREEZE COMET show that security depends on a combination of architecture, identity governance, credential management, monitoring, segmentation, operational processes, and the ability to respond.

PRODIST: Expertise in Cryptography and Security for Critical Financial Environments

Founded in 1987, PRODIST has been developing encryption and digital security solutions for financial transactions for 39 years.

The company keeps pace with developments in the National Financial System and has had solutions in operation since the launch of the Brazilian Payment System (SPB) in 2002, serving institutions that rely on security, stability, availability, and compliance in critical processes.

More than just meeting current technological requirements, operating in this market requires continuously keeping abreast of new threats, regulatory changes, and shifts in institutional architecture.

The rise of groups such as BREEZE COMET underscores precisely this need: as financial infrastructure evolves, so do the threats, and protective mechanisms must evolve alongside them.

Sources:

https://blog.google/intl/pt-br/produtos/nas-nuvens/breeze-comet-uma-ameaca-de-motivacao-financeira-no-brasil

FAQ – BREEZE COMET and Financial Market Security

What is BREEZE COMET?

BREEZE COMET is a financially motivated threat actor identified by the Google Threat Intelligence Group, previously tracked as UNC5669. The group targets organizations with access to financial systems and seeks to carry out fraudulent transfers.

Which organizations are targeted by BREEZE COMET?

The transactions observed involve organizations capable of conducting transactions through banking software, APIs, and systems such as Pix, STR, and boleto, including banks, fintech companies, payment processors, retailers, and financial software providers.

Is BREEZE COMET taking on Pix?

The group seeks to compromise organizations that have access to the infrastructure and credentials needed to carry out transactions, including those related to Pix. This is different from saying that the group compromised Pix’s central infrastructure.

How does BREEZE COMET gain access to companies?

Techniques such as password spraying, social engineering, remote access tools, compromised legitimate websites, malware, and even unauthorized physical devices connected to networks were observed.

Does BREEZE COMET use artificial intelligence?

There is evidence that large language models are being used to speed up tasks such as scripting, recognition, credential validation, deployment, and data extraction.

How can financial institutions reduce the risk of this type of attack?

The protection must combine identity and privilege management, multi-factor authentication, segmentation, monitoring, endpoint security, centralized secret management, and adequate protection of certificates and cryptographic keys.

Why is cryptographic key management important for financial security?

Keys and certificates can authenticate systems, secure communications, and enable critical operations. Therefore, they require controlled access, secure storage, traceability, and proper management throughout their entire lifecycle.

Photo by PRODIST
PRODIST

Technology for secure financial transactions. Prodist develops encryption and digital signature solutions for the Pix, SFN, NÚCLEA, and SPED ecosystems to meet the regulatory requirements of the financial market.

Share

More content

Talk to an expert

Fill out the form and find out how PRODIST can help your institution operate securely, in compliance, and at peak performance. We can help you with: