cloud.google.com
Breeze Comet Targets Brazilian Financial Sector with Systemic Fraud
Article Content
Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and eCommerce organizations, executing hundreds of fraudulent transactions via the Pix payment system. This group, previously known as UNC5669, employs tactics such as password spraying and social engineering to gain access to sensitive environments where payment orders are generated. Their operations have resulted in significant financial losses, with at least one heist amounting to tens of thousands of dollars. The group is known to exploit vulnerabilities in banking software and payment APIs, leveraging a customized malware suite and compromised websites for initial access. Recent reports indicate that Breeze Comet may be expanding its operations to other countries in Latin America and Africa. The overlap with other threat actors like Plump Spider highlights the complexity and interconnectedness of these cybercriminal activities. Organizations are urged to implement robust security measures to mitigate these evolving threats.
Key Points: • Breeze Comet has executed hundreds of fraudulent transactions in Brazil's financial sector. • The group uses advanced tactics, including social engineering and malware, to gain access to payment systems. • There is evidence of operational overlap with other threat actors like Plump Spider.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.