Breeze Comet Targets Brazilian Financial Sector with Fraudulent Transactions

Breeze Comet Targets Brazilian Financial Sector with Fraudulent Transactions

First seen 1 Sep 2026, 18:32 UTC Thehackernewscloud.google.comblog.axur.com 71.8

Article Content

Browse articles
ThreatCluster

Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and e-commerce organizations, successfully executing hundreds of fraudulent transactions. The group employs tactics such as password spraying and social engineering to gain initial access to payment systems. They have been linked to operations involving at least one heist worth tens of thousands of U.S. dollars. Breeze Comet's activities overlap with other threat clusters like Plump Spider and SHADOW-AETHER-064. Their operations utilize a customized malware suite and compromised trusted websites for command and control. The group is believed to be expanding its infrastructure to other Latin American and African countries. Key requirements for their attacks include access to the National Financial System Network and mTLS credentials for transaction orders. Current mitigation strategies are recommended for organizations to defend against this evolving threat.

Key Points: • Breeze Comet has targeted Brazilian financial services since 2024. • The group uses tactics like password spraying and social engineering for initial access. • They are expanding their operations beyond Brazil into Latin America and Africa.

Timeline

2024-01-01
Breeze Comet begins targeting Brazil
Mandiant starts investigating compromises in Brazilian financial services and retail sectors attributed to Breeze Comet.
cloud.google.com
2025-11-01
Notable attack reported
Breeze Comet successfully executed a heist worth tens of thousands of U.S. dollars, highlighting their operational capabilities.
Thehackernews
2026-09-01
Current threat assessment published
Google Threat Intelligence Group and Mandiant provide detailed insights into Breeze Comet's tactics and mitigation recommendations.
cloud.google.com