The flowchart of SHADOW-AETHER-040’s AI agent usage | Image: TrendMicro
At a Glance
- Actor or group: BREEZE COMET (formerly UNC5669, Plump Spider, SHADOW-AETHER-064)
- Activity type: Banking fraud, payment system manipulation, custom malware delivery
- Targets or victims: Brazilian banks, payment processors, fintechs, and retailers
- Scale: Hundreds of unauthorized transactions; claimed theft of tens of thousands of dollars
- Jurisdiction or law-enforcement status: Suspected financially motivated cybercriminal group
- Source: Google Threat Intelligence Group (GTIG) and Mandiant
TL;DR
Google Threat Intelligence Group identified recent BREEZE COMET threat actor attacks targeting Brazilian financial institutions. The cybercriminal syndicate compromises core banking software to execute fraudulent transfers across instant payment networks like Pix. Organizations must protect mutual TLS credentials and restrict cloud access to block these intrusions.
What Happened
In 2024, Mandiant investigators discovered widespread intrusions targeting financial services and retail companies across Brazil. The attackers breached enterprise networks to manipulate banking software and transfer processing pipelines directly. Furthermore, researchers from Trend Micro noted that the attackers exploited vulnerabilities in JBoss AS servers during initial intrusions.
The cybercriminals gained access to the National Financial System Network to interact with core payment services. Specifically, they targeted instant payment systems such as Pix, STR, and Boleto. To execute these transfers, the intruders obtained mutual TLS certificates from compromised servers. Security firm Axur confirmed that the group also used voice phishing calls to trick staff into installing remote monitoring utilities.
Multistage Infiltration Techniques
The attackers connected physical rogue hardware devices directly into retail store networks during 2025 incidents. Next, they moved laterally across internal networks using hijacked service accounts. They deployed custom tools to locate sensitive configuration files and API keys. As Mandiant researchers noted in their write-up, “The threat actor deployed the custom LDAP brute-forcing utility REALBREEZE.”
The intruders also searched continuous integration pipelines to extract cloud secrets. Additionally, they deployed custom backdoors to maintain access across multiple target environments. They used generative artificial intelligence tools to accelerate script creation. According to Google researchers, these scripts contain verbose comments and standardized execution headers.
Custom Backdoors and Evasion
The group relies on a custom malware toolkit built across several programming languages. For instance, they use a Rust network tunneler called COBALTSPIN to bypass perimeter firewalls. In addition, they deploy a Java backdoor named LIGHTPAINT to install SoftEther VPN connections. They also utilize KICKPLATE, a Nim-based tool that impersonates Windows Update utilities.
To hide ongoing activity, the intruders modify local Windows Defender Firewall rules. They clear system event logs to eliminate traces of remote logins. A detailed report on BREEZE COMET outlines how these custom backdoors evade standard detection.
Who Is Behind It
Google Threat Intelligence Group tracks this group as BREEZE COMET with high attribution confidence. The team previously monitored this cluster under the temporary designation UNC5669. Independent industry research links these operations to aliases such as Plump Spider and SHADOW-AETHER-064.
The group operates primarily as a financially motivated cybercriminal syndicate. Their operations show deep technical knowledge of Brazilian banking regulations and transactional systems. In addition, the operators compromise municipal government websites across Brazil, Ghana, Nigeria, and Venezuela to host malicious payloads. This global infrastructure helps them evade domain reputation filters during email campaigns.
Impact or Scale
The BREEZE COMET threat actor conducted aggressive payment operations against numerous commercial targets. In one documented intrusion, the attackers launched two rapid waves of hundreds of unauthorized transactions within 48 hours. As the report explains, “BREEZE COMET used COBALTSPIN and compromised privileged accounts to access core financial applications.”
The attackers allegedly stole tens of thousands of dollars in assets during a single financial heist. However, the total financial damage across all victim organizations remains an unconfirmed claim. The compromise of trusted banking credentials poses severe operational risks to payment processors and regional retail chains.
What Comes Next and How Readers Can Stay Protected
Security analysts expect this threat group to expand its operations across Latin America and Africa. Financial organizations must immediately review their transaction authorization workflows. Moreover, security teams need to protect mutual TLS certificates and private keys using hardware security modules.
Key Defensive Actions
Organizations should enforce strict network segmentation between corporate networks and core banking switches. System administrators must monitor PowerShell commands that attempt to disable real-time antivirus protections. Furthermore, companies should audit continuous integration pipelines to prevent the exposure of cloud access tokens. Implementing multi-factor authentication across all remote access tools remains vital to stopping unauthorized logins.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!