‘Breeze Comet’ Tears Into Brazilian & Global Financial Systems

A Highly Sophisticated Cybercrime Group is Hijacking Brazilian Financial Systems

A highly organized cybercrime group, known as Breeze Comet, has been making headlines for its brazen attacks on Brazilian financial systems. This group, which was previously known as UNC5669, has developed a clever strategy to infiltrate the country’s financial institutions and siphon off millions of dollars into its own pockets.

Breeze Comet targets organizations that handle sensitive financial transactions, including banks, financial services, fintech companies, retail, and e-commerce businesses. Using custom malware and creative tactics, it gains access to these systems by exploiting vulnerabilities in their payment infrastructure. Once inside, the group initiates payments to itself, often for tens of thousands of dollars at a time.

What’s particularly concerning is that Breeze Comet’s model may be replicable in other countries as well. Experts warn that this group’s tactics could work in many parts of the world where financial systems are similarly vulnerable. In fact, researchers have already observed attempts by the group to hack municipal websites in several countries, including Nigeria, Paraguay, Ghana, and Venezuela.

The group’s approach is multifaceted. Initially, they use standard intrusion techniques such as password spraying and vishing calls to install remote monitoring and management (RMM) software inside targeted organizations. However, their true intentions are masked by these tactics. In 2025, researchers discovered that Breeze Comet was trying to recruit insiders at targeted companies or connect its own hardware directly into retail store networks to establish an initial foothold.

Once connected, the group uses a range of custom malware tools to achieve privilege escalation, lateral movement, and persistence within the compromised systems. These tools include “RealBreeze,” which brute-forces Lightweight Directory Access Protocol (LDAP) directory servers, “LightPaint,” which installs a legitimate VPN for persistence, and “KickPlate,” which impersonates Windows Update Health Tools while modifying system files.

The use of generative AI in developing its malware has also been observed, which may further increase the scale, speed, and sophistication of Breeze Comet’s operations in the future. This development is particularly worrying as it indicates that this group is willing to invest in cutting-edge technology to stay ahead of security measures.

To prevent similar attacks from happening to their organizations, experts recommend implementing some quick fixes. These include deploying 802.1X Network Access Control (NAC) across physical Ethernet switch ports at branch or retail locations, disabling unused network switch ports, and physically restricting access to networking closets and public-facing jacks. Additionally, ensuring that all systems are properly segmented and updating software regularly can help prevent such attacks.

In conclusion, the highly sophisticated Breeze Comet group has demonstrated a willingness to adapt and innovate in its pursuit of financial gains. As this group continues to evolve, it’s essential for organizations worldwide to remain vigilant and take proactive measures to protect themselves against these types of threats.


Source: Dark Reading — 2026-09-03