‘Breeze Comet’ Tears Into Brazilian & Global Financial Systems

Brazil’s financial systems are under attack by a sophisticated cybercrime group known as Breeze Comet. This threat group has been making headlines with its brazen tactics, infiltrating Brazilian financial institutions to steal cash directly from their payment infrastructure.

Breeze Comet is not just a nuisance – it’s a highly motivated and skilled operation that targets the weakest points in financial systems. Its primary goal is to initiate payments to itself, often for tens of thousands of US dollars at a time. What makes this threat group particularly worrying is its ability to adapt and replicate its tactics in other regions. Researchers have observed attempts by Breeze Comet to hack municipal websites in countries like Nigeria, Paraguay, Ghana, and Venezuela.

Breeze Comet’s modus operandi begins with standard intrusion techniques such as password spraying and vishing calls impersonating IT support desks. These tactics mask the group’s true intentions and allow them to install remote monitoring and management (RMM) software inside targeted organizations. In some cases, hackers connect their own hardware directly into retail store networks to establish initial access points.

However, it was only in 2025 that researchers at Axur discovered Breeze Comet’s attempts to recruit insiders at targeted companies. The group would also leverage the trust associated with government websites by staging its malware on these sites and using them as a trusted domain for follow-on social engineering attacks against its actual targets.

What’s particularly concerning is that Breeze Comet has been observed using generative AI to develop its malware, which may further increase the scale, speed, and sophistication of their operations in the future. The group’s arsenal includes custom malware designed for privilege escalation, lateral movement, and persistence. Among these tools are “RealBreeze,” “LightPaint,” and “KickPlate.”

Researchers from Google Threat Intelligence Group (GTIG) and Mandiant have been studying Breeze Comet’s tactics and have identified some quick fixes to prevent this kind of attack on other organizations. They recommend deploying 802.1X Network Access Control across physical Ethernet switch ports at branch/retail locations, disabling unused network switch ports, and physically restricting access to networking closets and public-facing jacks.

As the threat landscape continues to evolve, it’s essential for financial institutions and government organizations to be vigilant in protecting their systems from sophisticated threats like Breeze Comet. With the group’s ability to adapt and replicate its tactics, it’s crucial that organizations implement robust security measures to prevent unauthorized access and stay ahead of this highly motivated cybercrime group.

In practical terms, what can you do to protect yourself? First, ensure your organization has robust network segmentation in place to prevent unauthorized devices from accessing internal networks. Second, regularly update and monitor your systems for signs of intrusion or malware activity. Finally, educate your employees on the dangers of phishing and vishing attacks, and implement security protocols that require multiple authentication steps for critical actions. By taking these precautions, you can reduce the risk of falling victim to Breeze Comet’s tactics and protect yourself from financial losses.


Source: Dark Reading — 2026-09-03