cloud.google.com
Breeze Comet Targets Brazilian Financial Sector with Fraudulent Transactions
Article Content
Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and e-commerce organizations, successfully executing hundreds of fraudulent transactions. The group employs tactics such as password spraying and social engineering to gain initial access to payment systems. They have been linked to operations involving at least one heist worth tens of thousands of U.S. dollars. Breeze Comet's activities overlap with other threat clusters like Plump Spider and SHADOW-AETHER-064. Their operations utilize a customized malware suite and compromised trusted websites for command and control. The group is believed to be expanding its infrastructure to other Latin American and African countries. Key requirements for their attacks include access to the National Financial System Network and mTLS credentials for transaction orders. Current mitigation strategies are recommended for organizations to defend against this evolving threat.
Key Points: • Breeze Comet has targeted Brazilian financial services since 2024. • The group uses tactics like password spraying and social engineering for initial access. • They are expanding their operations beyond Brazil into Latin America and Africa.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.