BREEZE COMET Attacks Brazilian Banks

Banking trojans typically target individual retail customers. However, the BREEZE COMET group selected significantly larger targets. The Google Threat Intelligence Group recently exposed this dangerous organization. Since 2024, they successfully penetrated Brazilian banks, fintech companies, payment services, and retail stores. Their primary goal involves executing massive money transfers directly on behalf of these organizations.
Infiltrating Financial Networks
Criminals require specific access to extract these funds successfully. They must penetrate the RSFN financial network and secure payment interfaces. Furthermore, they need mutual TLS (mTLS) authentication certificates. The group meticulously studies transfer processing via the Pix system. They also analyze the STR backup system and Boleto bank receipts. Subsequently, they hunt for privileged accounts capable of sending confirmed payment commands.
Evolving Initial Access Methods
Initial intrusions frequently began with simple password spraying and deceptive technical support calls. Attackers actively persuaded employees to install AnyDesk alongside other remote management tools. Later, BREEZE COMET adopted more sophisticated tactics. They hosted XWORM and various loaders directly on compromised municipal websites. In one remarkable incident, they physically connected a malicious device directly into a retail store’s local network.
Navigating Internal Infrastructure
Once inside the infrastructure, the group actively harvested sensitive data. They stole API keys, cloud tokens, and certificates directly from Active Directory. They also targeted development environments and CI/CD pipelines. They utilized COBALTSPIN to move laterally between isolated network segments. This specific tool functions as a network tunnel written entirely in Rust. Furthermore, they deployed several custom backdoors developed in Java, Nim, and Go. These backdoors successfully maintained redundant access channels while cleverly disguising malicious traffic as standard services.
Executing the Heist
After acquiring access to the core banking system, BREEZE COMET acted swiftly. They executed two distinct series involving hundreds of unauthorized transfers. These massive operations concluded within a tight 24-to-48-hour window. In at least one confirmed episode, the group successfully stole tens of thousands of dollars. Following the extraction, the attackers meticulously purged event logs. They also deleted created directories to completely conceal their interaction with the payment interfaces.
AI Integration and Defensive Measures
Google investigators also discovered compelling evidence indicating the use of generative AI. The group utilized AI to prepare reconnaissance scripts and verify complex banking details. They even used it to rapidly deploy tools across multiple networks simultaneously. Security experts offer strong recommendations to defend against these advanced tactics. Organizations must immediately block all unauthorized remote access tools. They must implement robust, phishing-resistant multi-factor authentication. Furthermore, they should decisively close all unused network ports. Finally, strictly separating core payment systems from standard employee workstations remains absolutely essential.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.