Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

**Brazilian Payment Systems Hit by Sophisticated Fraud Scheme**

A recent wave of coordinated attacks on Brazilian payment systems has left hundreds of unsuspecting victims financially exposed. Breeze Comet, a highly sophisticated malware strain, has been successfully used to execute massive numbers of fraudulent transactions across multiple platforms. The attackers’ modus operandi is centered around exploiting vulnerabilities in cross-domain privilege escalation, which allows them to bypass security measures and access sensitive data.

The Brazilian payment systems targeted by the attackers are primarily based on online banking platforms, allowing users to transfer funds between accounts via mobile apps or websites. When a user attempts to initiate a transaction, their device interacts with the payment system’s backend infrastructure, which is responsible for validating and executing the request. In this case, the attackers exploited vulnerabilities in cross-domain privilege escalation, a technique used to elevate privileges on one domain to access another.

By leveraging these vulnerabilities, Breeze Comet gains unauthorized access to sensitive data, including financial information and authentication credentials. This allows the attackers to create fake accounts, simulate legitimate transactions, and eventually drain victims’ accounts of their funds. The attackers’ goal is to remain undetected for as long as possible, using the stolen funds to further finance their malicious activities.

The Brazilian authorities have been informed about the situation, but it remains unclear how many more attacks may be carried out before the issue is fully addressed. Experts warn that this type of attack could spread to other countries with similar payment systems, emphasizing the need for robust security measures and collaboration between financial institutions.

As this high-profile case unfolds, cybersecurity experts are urging users to remain vigilant when dealing with online banking transactions. This means regularly updating software, using strong passwords, and being cautious of suspicious activity on accounts. Furthermore, individuals should be aware that their devices may be compromised even if they themselves have not engaged in any malicious behavior.

For those who believe they may be victims of Breeze Comet attacks, it’s essential to act quickly to limit potential damage. Users are advised to freeze their accounts, change passwords, and monitor for suspicious activity on their financial statements.


Source: The Hacker News — 2026-09-01