BREEZE COMET is a financially motivated threat actor that targets Brazilian financial services, retail, and eCommerce organizations by abusing compromised websites, custom malware, and stolen credentials to manipulate payment systems and fraudulent transfers. The group has also used generative AI to accelerate malware and script development, while expanding its infrastructure and tactics across Latin America and Africa. #BREEZECOMET #COBALTSPIN #REALBREEZE #MILDFROST #KICKPLATE #BOATBEAM #XWORM #ANYDESK
Keypoints
- BREEZE COMET (formerly UNC5669) is a financially motivated threat actor focused on fraudulent transfers through Brazilian banking and payment systems.
- The group targets organizations with access to Pix, STR, Boleto, RSFN, mTLS credentials, and financial APIs, including banks, fintechs, retailers, and payment processors.
- Initial access has included password spraying, voice phishing impersonating IT support, RMM tools like AnyDesk, compromised government websites, and rogue hardware devices placed in retail networks.
- BREEZE COMET uses custom tools such as REALBREEZE, COBALTSPIN, KICKPLATE, MILDFROST, LIGHTPAINT, and BOATBEAM to support reconnaissance, lateral movement, persistence, tunneling, and stealth.
- The group abuses Windows, Active Directory, cloud, CI/CD, SMB, RDP, and Kubernetes environments to steal credentials, deploy backdoors, and maintain redundant access.
- Mandiant observed the actor clearing logs, deleting directories, and disabling Windows Defender real-time monitoring to hide activity and preserve access.
- Forensic evidence shows BREEZE COMET executed waves of fraudulent transactions within 24-48 hours of compromise and has likely stolen tens of thousands of USD in assets.
MITRE Techniques
- [T1110.003] Password Spraying â Used during early compromises to gain access by attempting many passwords against accounts (âuse password sprayingâ).
- [T1204.004] User Execution: Malicious Copy and Paste â Social engineering encouraged users to install RMM tools after voice calls impersonating IT support (âconvince users to install Remote Monitoring and Management (RMM) toolsâ).
- [T1566.004] Phishing: Voice Phishing â Threat actors impersonated IT support over voice calls to trick users into installing tools (âvoice calls impersonating IT support teamsâ).
- [T1021.001] Remote Services: Remote Desktop Protocol â Hijacked service accounts were used to initiate unauthorized RDP sessions (âinitiate unauthorized Remote Desktop Protocol (RDP) sessionsâ).
- [T1021.002] Remote Services: SMB/Windows Admin Shares â Commands were executed via SMB network file shares and internal scanning focused on SMB pathways (âexecute commands via SMB network file sharesâ).
- [T1057] Process Discovery â Recon utilities and scripts were used to identify systems and available resources within compromised environments (âreconnaissance utilities such as Impacket, ADRecon and ADVipscanâ).
- [T1082] System Information Discovery â Custom scripts searched host files and environment variables for credentials and system details (âsearch internal host files and environmental variablesâ).
- [T1555] Credentials from Password Stores â The actor stole hard-coded pipeline credentials, API keys, and cloud access tokens from CI/CD environments (âsteal hard-coded pipeline credentialsâ).
- [T1003.002] OS Credential Dumping: Security Account Manager â REALBREEZE brute-forced LDAP and the group harvested credentials from internal systems (âcustom LDAP brute-forcing utility REALBREEZEâ).
- [T1068] Exploitation for Privilege Escalation â Trend Micro reported exploitation of JBoss AS servers to gain initial access (âexploited vulnerabilities in JBoss AS serversâ).
- [T1018] Remote System Discovery â Network scanning across internal subnets was used to enumerate hosts and SMB pathways (âexecuting network scanning tools across internal subnetsâ).
- [T1021.004] Remote Services: SSH â Scripts included scanning for SSH ports on Linux systems (âSTEP 1: ENUM ALL LINUX (SSH PORT 22)â).
- [T1090.001] Proxy: Internal Proxy â COBALTSPIN created a reverse SOCKS5 proxy over WebSocket to route traffic and maintain access (âreverse SOCKS5 proxy over a WebSocket connectionâ).
- [T1090.003] Proxy: Multi-hop Proxy â Specialized tunneling was used to move traffic through boundary firewalls and segmented networks (âcommunicate and maintain persistent network accessâ).
- [T1095] Non-Application Layer Protocol â COBALTSPIN used network tunneling and DNS-based channels to communicate with C2 (âestablish slow, covert DNS tunnelsâ).
- [T1090.002] Proxy: External Proxy â Compromised trusted websites were used as staging and C2 infrastructure (âcompromised, trusted websitesâ).
- [T1190] Exploit Public-Facing Application â Rogue hardware and compromised websites, plus reported JBoss exploitation, were used to reach internal environments (âexploit vulnerabilities in JBoss AS serversâ).
- [T1059.001] Command and Scripting Interpreter: PowerShell â PowerShell was used for in-memory execution, downloads, and Defender tampering (âexecuted in memory via PowerShellâ).
- [T1105] Ingress Tool Transfer â Malware, RMM tools, and scripts were downloaded from GitHub, open directories, and compromised sites (âdownloaded the Netcat utilityâ).
- [T1074.001] Data Staged: Local Data Staging â Files and payloads were staged on compromised government and municipal websites for delivery (âused compromised Brazilian small government websites to stage RMM toolsâ).
- [T1071.001] Application Layer Protocol: Web Protocols â C2 and exfiltration used web infrastructure such as paste sites and HTTPS servers (âfake IIS HTTPS server on port 443â).
- [T1041] Exfiltration Over C2 Channel â Cloud secrets were exfiltrated to public notepad sites (âexfiltrating them to public facing notepad websitesâ).
- [T1562.001] Impair Defenses: Disable or Modify Tools â Windows Defender real-time monitoring was disabled to keep malware operational (âDisableRealtimeMonitoring $trueâ).
- [T1562.006] Impair Defenses: Indicator Blocking â Event logs were cleared to erase forensic evidence (âcleared event logs across compromised hostsâ).
- [T1070.001] Indicator Removal on Host: Clear Windows Event Logs â The actor cleared event logs after activity to hide movement and API use (âcleared event logs across compromised hostsâ).
- [T1070.004] Indicator Removal on Host: File Deletion â Directories created during the compromise were deleted (âdeleted directories they had created during the compromiseâ).
- [T1053.005] Scheduled Task/Job: Scheduled Task â Malicious scheduled tasks were used for persistence via schtasks.exe (âabusing native scheduled tasks (schtasks.exe running as SYSTEM)â).
- [T1547.001] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder â KICKPLATE and shortcut changes were used to persist through startup mechanisms (âmodify Windows servicesâ and âshortcut (.lnk) modifications in user startup foldersâ).
- [T1136.001] Create Account: Local Account â Compromised accounts across AD and cloud environments were maintained to preserve access (âpersistent access to multiple accountsâ).
- [T1203] Exploitation for Client Execution â Malicious documents and staged payloads were used to trigger execution on victim systems (âinfostealers disguised as legitimate tax or receipt documentsâ).
- [T1584.001] Compromise Infrastructure: Domains â Trusted municipal and government domains were compromised for staging and delivery (âcompromised Brazilian small government websitesâ).
- [T1584.006] Compromise Infrastructure: Web Services â Paste services and cloud-hosted web resources were used for exfiltration and staging (âdontpad[.]comâ).
Indicators of Compromise
- [File hashes] Malware samples for custom tooling â 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec, 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a, and other 6 items
- [File names] Staged or deployed payloads and loaders â ComprovantePDF.exe, Comprovantepdf.exe, and other 6 items
- [Domains / URLs] Compromised staging and delivery sites â dontpad[.]com, procon[.]go[.]gov[.]br/ComprovantePDF[.]exe, and other 16 items
- [File names] Custom backdoors and tooling referenced in detections â COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, KICKPLATE, XWORM
- [Network indicators] Paste site used for data exfiltration and payload hosting â dontpad[.]com, hxxps://procon[.]go[.]gov[.]br/ComprovantePDF[.]exe