www.crowdstrike.com
Slim Spider Targets Brazilian Financial Institutions for Crypto Theft
Article Content
A newly identified cybercriminal group, Slim Spider, has been linked to attacks on Brazilian financial institutions since March 2026. The group demonstrates advanced knowledge of Brazil's financial infrastructure, including the Pix instant payment service and cloud environments. Their attack method involves multi-stage intrusions, utilizing custom Bash scripts to extract cloud credentials and secrets related to digital assets. They have been observed deploying backdoors and malicious pipelines within Azure DevOps, affecting managed Kubernetes clusters. The threat actor's tools include custom scripts for credential extraction and unauthorized transaction execution. CrowdStrike is actively tracking this group and has reported on their sophisticated operational security measures. The attacks have led to the exfiltration of sensitive cryptocurrency custody secrets.
Key Points: • Slim Spider is targeting Brazilian financial institutions since March 2026. • The group uses custom Bash scripts to steal cloud credentials and digital asset secrets. • Attacks involve deploying backdoors and malicious pipelines in cloud environments.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.