Breeze Comet Brazilian payment-system fraud campaign
Campaign
Summary
Hide ▲
Show ▼
Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting payment systems and banking software at risk. The operation uses password spraying, IT-support impersonation, AnyDesk and other RMM tools, and JBoss AS web shells to reach internal environments and manipulate transactions. It has already enabled fraudulent transfers and hundreds of fraudulent transactions, making the campaign a direct threat to banks, payment processors, retailers, exchanges, and fintech providers.
Related Happenings
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor Meta
H score27
First: 01.09.2026 20:19
Last: 01.09.2026 20:19
Sources 1
How related:
According to CrowdStrike, the e-crime group is operating out of Brazil and has been active since September 2023, monetizing their intrusions by gaining unauthorized access to internal payment systems and carrying out fraudulent transactions.
About this happening:
Researchers have profiled Breeze Comet as a Brazil-based e-crime group with overlapping aliases and a monetization model centered on fraudulent transfers. The cluster'...
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor MetaHow related: According to CrowdStrike, the e-crime group is operating out of Brazil and has been active since September 2023, monetizing their intrusions by gaining unauthorized access to internal payment systems and carrying out fraudulent transactions.
About this happening: Researchers have profiled Breeze Comet as a Brazil-based e-crime group with overlapping aliases and a monetization model centered on fraudulent transfers. The cluster'...
Timeline
-
01.09.2026 20:19 2 articles · 3h ago
Breeze Comet targets Brazilian payment systems for fraudulent transfers
Initial DisclosureBreeze Comet, formerly UNC5669, is described as a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since 2024, with Google Threat Intelligence Group and Mandiant saying it specializes in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. The campaign is associated with unauthorized access to internal payment systems, use of password spraying and IT-support impersonation, installation of RMM tools such as AnyDesk, exploitation of vulnerable JBoss AS servers with web shells, and follow-on tooling including Chisel, COBALTSPIN, and custom backdoors used to maintain access to financial API infrastructure.
Show sources
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — thehackernews.com — 01.09.2026 20:19
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — thehackernews.com — 01.09.2026 20:19