"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities' cloud environments," CrowdStrike said.
Slim Spider's March 2026 intrusion at a Brazil-based financial institution
CrowdStrike traces a previously undocumented financially motivated actor, which it calls Slim Spider, to activity against Brazilian financial institutions dating back to at least March 2026. In an observed multi-stage intrusion that month, the group set its sights on a Brazil-based financial institution's cryptocurrency assets and instant payment accounts. The campaign began in cloud environments and escalated into lateral movement across containers and DevOps pipelines with the explicit goal of accessing digital asset custody credentials.
How Slim Spider stole cloud credentials and custody secrets
CrowdStrike describes the actor using custom Bash scripts to query cloud instance metadata and steal temporary cloud credentials over socket connections. Once inside the environment, the adversary enumerated secrets from the cloud credential manager, then used the "sed" command to clone and modify secret-extracting scripts—targeting specifically credentials tied to digital financial assets.
After exfiltrating custody secrets, Slim Spider invoked cast, a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key. Rather than using third-party libraries, the actor implemented cloud-native cryptographic signing directly via OpenSSL inside Bash scripts—a deliberate operational choice CrowdStrike says reduced detection risk and reflected "sophisticated operational security awareness and a nuanced understanding of cloud environments."

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageImpersonation, implants, and pipeline abuse: Azure DevOps and Kubernetes
The intrusion included movement into nodes running in a cloud container service cluster and deployment of backdoors that mimicked infrastructure-related binaries to blend with legitimate tooling. CrowdStrike observed likely credential-based compromise of Azure DevOps to run malicious pipelines. Those pipelines deployed additional implants across a managed Kubernetes cluster; one implant was named "spi," an attempt to impersonate Sistema de Pagamentos Instantâneos (SPI), the central digital infrastructure that processes Pix payments in Brazil.
Among the tools attributed to the actor is MikeDor, described by CrowdStrike as a Go-based backdoor that can harvest sensitive information and monitor user activity. The vendor warned that Slim Spider's targeting of credentials associated with custody systems gives the actor direct paths to high‑value digital currency assets, with the potential for "devastating financial loss for victims."
Automation panels, exposed C2, and bulk Pix abuse
CrowdStrike linked Slim Spider to several web-based panels that automate parts of the attack chain. These include:
- NEXUS // Scanner — an API endpoint-scanning panel that uses Ollama to categorize endpoints into 16 types (fintech, banking, payment, cryptocurrency, and others) and rank them on availability and authentication options;
- Painel de Emails Entra ID — an email reconnaissance panel that searches compromised Microsoft 365 mailboxes and sorts them into finance, admin, and Brazil categories;
- Painel Pix — a transaction panel designed to execute bulk unauthorized Pix transfers from compromised accounts.
CrowdStrike also said it discovered an exposed command-and-control (C2) panel that displayed several compromised hosts from multiple Brazil-based banks and fintech organizations and likely exfiltrated archive files. The presence of scanning, mailbox reconnaissance, transaction automation, and an exposed C2 suggests a tightly integrated toolset aimed at moving from initial access to rapid, automated financial abuse.
Breeze Comet (CL-CRI-1163 / Plump Spider / SHADOW-AETHER-064) — a concurrent wave hitting Pix and payment rails
The disclosure of Slim Spider coincides with reporting on another Portuguese-speaking actor dubbed Breeze Comet — also tracked as CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064 — which Google Threat Intelligence Group (GTIG) and Mandiant say has been infiltrating Brazilian financial systems since as early as 2024. GTIG and Mandiant describe Breeze Comet breaking into systems used to perform transactions and initiating payments for itself, staging malware on insufficiently secure Brazilian government websites and leveraging the sites' reputation in follow-on social engineering.
Breeze Comet's goal, according to GTIG and Mandiant, is access to the financial applications used to make payments — Pix, Boleto, and the Reserves Transfer System (STR) — and execution of hundreds of fraudulent transactions. The group has reportedly attempted to replicate the tactic in municipalities outside Brazil, including in Nigeria, Paraguay, Ghana, and Venezuela.
What this means for technologists, policymakers, and Brazilian financial institutions
- Technologists and security teams: CrowdStrike's findings point to credential-targeting in cloud metadata, DevOps pipeline compromise, and cloud-native cryptographic operations; teams will need to prioritize detection and hardening of cloud instance metadata access, credential manager auditing, and pipeline integrity.
- Policymakers and regulators: The use of infrastructure impersonation (an implant named "spi") and automated Pix-transfer tooling underscores risks to instant payment rails; regulators responsible for payment-system integrity and incident reporting will likely watch for pipeline and custody-credential compromises that enable large-scale fraud.
- Brazilian financial institutions and fintechs: The combination of backdoors, automated transaction panels, and exposed C2 servers tied to banks and fintech organizations suggests immediate operational risk—particularly for custody services and systems that interface with Pix and other payment rails.
The record assembled by CrowdStrike, GTIG, and Mandiant shows two parallel trends: actors probing and compromising cloud-native financial infrastructure with increasing sophistication, and a move from high-volume retail fraud toward direct intrusion of payment switches and custody systems. Whether banks, cloud providers, and payment operators adapt their controls quickly enough to stem credential theft and automated abuse will determine how many incidents remain isolated and how many become systemic.




