"Breeze Comet tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command‑and‑control (C2), and to interact with financial software and payment APIs," Google said.
Breeze Comet's operational scope and known impact
Since 2024 a financially motivated threat actor identified as Breeze Comet (formerly UNC5669) has focused on Brazilian financial services, retail, and e‑commerce organizations, according to joint reporting from Google Threat Intelligence Group (GTIG) and Mandiant teams. The group has been tied to at least one successful heist that moved assets worth "tens of thousands of U.S. dollars." GTIG warned the actor may seek to expand operations into other countries in Latin America and Africa.
How Breeze Comet gains initial access
Researchers say the group uses a mix of social engineering and exposed internet services to get in. Initial access techniques include password spraying and voice calls in which operators impersonate IT support to convince targets to install Remote Monitoring and Management (RMM) tools such as AnyDesk. In a documented case reported by Axur in November 2025, attackers impersonated IT support over WhatsApp and guided a victim to install a PowerShell reconnaissance script under the pretext of updating a corporate application. Breeze Comet has also exploited vulnerable JBoss AS servers to install web shells and then deliver follow‑on tooling.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageTools observed: proxies, backdoors, and COBALTSPIN
The intrusion chain routinely uses tunneling and proxy utilities to reach internal payment systems. Reported tooling includes Chisel and other proxy utilities for follow‑on exploitation, and the group frequently deploys Netcat and custom scripts after establishing a foothold. Researchers highlighted COBALTSPIN, a Rust‑based routing malware that operates as a network tunneler and establishes a reverse SOCKS5 proxy over a WebSocket connection to route traffic between C2 infrastructure and internal targets—enabling lateral movement through boundary firewalls without relying on traditional persistence that might be more detectable.
- Compromised small government websites have been used as staging locations for RMM tools, infostealers, and backdoors, and as C2 endpoints to evade reputation filters.
- Rogue hardware inserted into retail store networks has been used to gain a direct foothold and then move laterally into internal systems.
- Internal reconnaissance and privilege escalation tools observed include Impacket, ADRecon, ADVipscan, and a custom LDAP brute‑forcer called REALBREEZE.
- Post‑exploitation frequently includes unauthorized RDP sessions, SMB command execution, and clearing event logs and directories to minimize forensic traces.
Custom backdoors, cloud stealth, and LLM‑style code
GTIG reports a growing, partly bespoke malware suite used to maintain access and interact with financial APIs. Notable backdoors and components include:
- LIGHTPAINT — a Java-based backdoor used to install SoftEther VPN and configure it for automated persistence.
- MILDFROST — a passive Java JAR backdoor employed to establish covert DNS tunnels.
- KICKPLATE — a Nim-based backdoor that impersonates Windows Update Health Tools to deliver secondary payloads and control SOCKS5 tunnelers.
- BOATBEAM — a Golang backdoor that initiates a fake IIS HTTPS server on port 443.
Persistence tactics evolved from dropping commercial RMM tools in 2024 to deploying malicious Kubernetes pods in 2025 and exfiltrating cloud secrets to public notepad sites such as dontpad[.]com. Researchers also note verbose explanatory comments and standardized execution headers in some malware, and Trend Micro's May 2026 analysis found scripts containing "descriptions of self‑reasoning and autonomous decision‑making processes," a pattern GTIG links to the use of a large language model (LLM) to compress the malware development lifecycle.
Requirements to attack Pix, STR, Boleto and the RSFN
GTIG outlined four concrete prerequisites for Breeze Comet's attacks against Brazil's instant and core payment rails: access to the National Financial System Network (RSFN) via an entity that already has that access; possession of mTLS credentials that allow sending authenticated transactional orders to Pix or STR; control over multiple accounts in the targeted organization's Active Directory and cloud environments; and a detailed understanding of transfer processing procedures, network controls, fintech integrations, and anti‑fraud systems. When those conditions are met, the final stage involves using COBALTSPIN and compromised privileged accounts to access core financial applications and execute hundreds of fraudulent transactions before deleting logs and directories to cover tracks.
What this means for banks, security teams, and regulators
Banks and payment processors: The actor's requirement for RSFN access and mTLS credentials makes institutions that hold or broker those capabilities direct targets; protecting credential issuance, monitoring for abnormal mTLS use, and hardening privileged accounts are immediate priorities.
Security teams and technologists: Defenders need to watch for social engineering to install RMM tools, web‑shell activity on JBoss AS servers, deployment of COBALTSPIN and SOCKS5 tunneling, disabling of Windows Defender real‑time monitoring via PowerShell, and exfiltration to public notepad services like dontpad[.]com.
Regulators and oversight bodies: The shift GTIG describes—from high‑volume retail fraud toward direct intrusions into core payment switches and instant payment infrastructure—raises systemic questions about the resilience of interbank networks and the cross‑border reach of financially motivated groups reported to be expanding into other regions.
Breeze Comet's campaigns are notable for combining tried‑and‑true social engineering with increasingly sophisticated tooling and bespoke backdoors. The result, researchers warn, is a faster adversary lifecycle and a heightened ability to operate inside payment rails. For organizations with any role in Brazil's payment ecosystem, the reporting offers a clear, specific checklist of what the attacker needs and the techniques they use—facts that narrow the defensive task even as the adversary broadens its toolkit.
https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html




