Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet has targeted Brazilian financial services, retail, and e-commerce organizations since 2024, using phishing, RMM tools, vulnerable servers, and custom malware to gain access to banking and payment systems. The group has evolved into a highly capable threat actor that executes fraudulent transfers, maintains persistence across cloud and on-premises environments, and may be expanding operations beyond Brazil. #BreezeComet #UNC5669 #Pix #STR #Boleto #COBALTSPIN #LIGHTPAINT #MILDFROST #KICKPLATE #BOATBEAM #REALBREEZE

Keypoints

  • Breeze Comet targets Brazilian organizations with access to banking software and payment infrastructure.
  • The group gains initial access through password spraying, impersonation, and malicious RMM tools.
  • It also exploits vulnerable JBoss AS servers and compromised websites to deliver payloads.
  • Custom tools like COBALTSPIN, LIGHTPAINT, and MILDFROST support tunneling, persistence, and lateral movement.
  • Stolen credentials and compromised accounts are used to perform fraudulent transactions and erase traces.

Read More: https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html