Slim Spider Targets Brazilian Financial Institutions for Crypto Theft

Slim Spider Targets Brazilian Financial Institutions for Crypto Theft

First seen 8 Sep 2026, 17:13 UTC Thehackernewswww.crowdstrike.comwww.virustotal.com 68.2

Article Content

Browse articles
ThreatCluster

A newly identified cybercriminal group, Slim Spider, has been linked to attacks on Brazilian financial institutions since March 2026. The group demonstrates advanced knowledge of Brazil's financial infrastructure, including the Pix instant payment service and cloud environments. Their attack method involves multi-stage intrusions, utilizing custom Bash scripts to extract cloud credentials and secrets related to digital assets. They have been observed deploying backdoors and malicious pipelines within Azure DevOps, affecting managed Kubernetes clusters. The threat actor's tools include custom scripts for credential extraction and unauthorized transaction execution. CrowdStrike is actively tracking this group and has reported on their sophisticated operational security measures. The attacks have led to the exfiltration of sensitive cryptocurrency custody secrets.

Key Points: • Slim Spider is targeting Brazilian financial institutions since March 2026. • The group uses custom Bash scripts to steal cloud credentials and digital asset secrets. • Attacks involve deploying backdoors and malicious pipelines in cloud environments.

Ask AI about this cluster

Timeline

2026-03-01
Slim Spider begins targeting Brazilian financial institutions
CrowdStrike links Slim Spider to a series of attacks aimed at financial entities in Brazil.
The Hacker News
2026-03-15
Multi-stage intrusion observed
Slim Spider orchestrates a multi-stage attack focusing on cryptocurrency assets and instant payment accounts.
The Hacker News
2026-09-08
CrowdStrike reports on Slim Spider
CrowdStrike publishes detailed analysis of Slim Spider's tactics and tools, including custom scripts and Azure DevOps exploitation.
CrowdStrike