Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

A financially motivated threat actor known as Breeze Comet (previously UNC5669) has been targeting Brazilian financial services, retail, and e-commerce companies since 2024.

The threat actor was identified by the Mandiant and Google Threat Intelligence Group (GTIG) teams as “specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.” At least one theft of assets valued at tens of thousands of dollars is reportedly successfully completed by the adversary.

The activity is similar to threat activity clusters that Trend Micro and CrowdStrike are monitoring under the names SHADOW-AETHER-064 and Plump Spider. The Brazilian e-crime group has been active since September 2023, according to CrowdStrike. They make money off of their attacks by obtaining unauthorized access to internal payment systems and conducting fraudulent transactions.

Password spraying and voice calls posing as IT support teams are used to get initial access to financial organizations and businesses providing financial services in order to convince targets to install Remote Monitoring and Management (RMM) technologies like AnyDesk read more about Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *