Breeze Comet has targeted Brazilian financial services, retail, and e-commerce organizations since 2024, using phishing, RMM tools, vulnerable servers, and custom malware to gain access to banking and payment systems. The group has evolved into a highly capable threat actor that executes fraudulent transfers, maintains persistence across cloud and on-premises environments, and may be expanding operations beyond Brazil. #BreezeComet #UNC5669 #Pix #STR #Boleto #COBALTSPIN #LIGHTPAINT #MILDFROST #KICKPLATE #BOATBEAM #REALBREEZE
Keypoints
- Breeze Comet targets Brazilian organizations with access to banking software and payment infrastructure.
- The group gains initial access through password spraying, impersonation, and malicious RMM tools.
- It also exploits vulnerable JBoss AS servers and compromised websites to deliver payloads.
- Custom tools like COBALTSPIN, LIGHTPAINT, and MILDFROST support tunneling, persistence, and lateral movement.
- Stolen credentials and compromised accounts are used to perform fraudulent transactions and erase traces.
Read More: https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html