Breeze Comet targets Brazilian payments
A threat actor known as Breeze Comet has been manipulating Brazilian payment systems since 2024, executing hundreds of fraudulent transactions after gaining access through social engineering and exploiting vulnerabilities.

A financially motivated threat actor dubbed Breeze Comet has been targeting Brazilian financial, retail, and e-commerce organizations since 2024. The group, described by Google's Threat Intelligence Group and Mandiant as specializing in manipulating payment systems to conduct fraudulent transfers, has successfully stolen assets worth tens of thousands of dollars in at least one heist. CrowdStrike and Trend Micro track overlapping activity under the names Plump Spider and SHADOW-AETHER-064.
Initial Access and Reconnaissance
Breeze Comet gains initial access through password spraying and voice calls impersonating IT support to trick targets into installing Remote Monitoring and Management (RMM) tools like AnyDesk. The group also targets vulnerable JBoss AS servers to deploy web shells. These shells deliver additional tools, including Chisel and other proxy utilities, for follow-on exploitation. Primary targets are organizations with access to banking software, APIs, and payment systems like Pix, STR, and Boleto. This includes banks, payment processors, retailers, exchanges, fintechs, and banking software providers.
To operate, the group must meet four requirements: access to the National Financial System Network (RSFN) through a member entity; possession of mTLS credentials for sending authenticated transactional orders; access to multiple accounts in target Active Directory and cloud environments; and an understanding of the organization's transfer procedures, network controls, and anti-fraud systems.
Evolving Tactics and Infrastructure
Google reports that Breeze Comet's tactics have evolved to leverage a customized malware suite and compromised, trusted websites for initial access, command-and-control, and interaction with financial APIs. The group's operational infrastructure may indicate intent to expand to other Latin American and African countries.
Notable tactics include using compromised small Brazilian government websites to stage RMM tools, infostealers disguised as tax documents, and backdoors like XWorm. These sites also serve as C2 endpoints to bypass reputation filters. This method has been replicated in Nigeria, Paraguay, Ghana, and Venezuela.
The actors sometimes connect rogue hardware devices directly into retail store networks to establish a foothold. They then move laterally, downloading Netcat and custom scripts to retrieve post-exploitation frameworks. For internal reconnaissance and privilege escalation, they use tools like Impacket, ADRecon, ADVipscan, and a custom LDAP brute-forcing utility called REALBREEZE, targeting development and cloud environments.
Lateral movement involves initiating unauthorized RDP sessions and executing commands via SMB file shares. This step includes deploying COBALTSPIN, a Rust-based routing malware that acts as a network tunneler.
Persistence Mechanisms and Final Fraud
Breeze Comet's persistence methods have evolved from dropping commercial RMM tools in 2024 to deploying malicious Kubernetes pods in 2025 and exfiltrating cloud secrets to public-facing notepad websites. The group now uses multiple custom backdoors for redundant access, including LIGHTPAINT (Java), MILDFROST (Java), KICKPLATE (Nim), and BOATBEAM (Golang). To ensure these mechanisms go undetected, the threat actor executes PowerShell commands to disable Windows Defender's real-time monitoring on compromised hosts.
In the final stage, the group uses COBALTSPIN and compromised privileged accounts to access core financial applications and execute hundreds of fraudulent transactions. Once complete, they clear event logs to minimize the forensic footprint and conceal API interactions with financial software. Any directories created during the intrusion are also deleted.
Analysts note the presence of verbose explanatory comments and standardized execution headers in the malware, indicating the use of a large language model (LLM) to compress the development lifecycle. Google warns that Breeze Comet's campaigns represent a notable shift in the Latin American cybercrime ecosystem, from opportunistic retail banking fraud to direct intrusions into core financial infrastructure.





