Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented threat actor called Slim Spider has been targeting Brazilian financial institutions since at least March 2026, with a focus on cloud environments, cryptocurrency assets, and Pix payment infrastructure. CrowdStrike also linked Slim Spider and Breeze Comet to sophisticated operations that steal credentials, deploy backdoors, and abuse Brazilian payment systems for fraudulent transactions. #SlimSpider #BreezeComet #Pix #SPI #MikeDor #AzureDevOps

Keypoints

  • Slim Spider is a Brazil-based threat actor targeting financial institutions.
  • The group steals cloud credentials and hunts for digital asset secrets.
  • Attackers used custom Bash scripts and OpenSSL for stealthy cloud abuse.
  • Slim Spider deployed backdoors and abused Azure DevOps and Kubernetes.
  • Breeze Comet is also targeting Brazilian payment systems like Pix and STR.

Read More: https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html