Breeze Comet-CL-CRI-1163-Plump Spider alliance reshapes ransomware ecosystem operations
Threat Actor Meta
Summary
Hide ▲
Show ▼
Breeze Comet is pushing Latin American cybercrime away from client-side retail fraud and toward direct intrusions into payment infrastructure, increasing risk to Brazilian financial systems and instant-transfer rails. The group's activity has expanded beyond Brazil to municipal websites in other countries, creating a reusable path for fraudulent transactions and follow-on social engineering.
Related Happenings
Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure
Campaign
H score34
First: 08.09.2026 19:20
Last: 08.09.2026 19:20
Sources 1
How related:
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.
About this happening:
The Slim Spider campaign is tied to multi-stage intrusions against Brazilian financial institutions, putting Pix transfers and cryptocurrency custody secrets a...
Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure
CampaignHow related: A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.
About this happening: The Slim Spider campaign is tied to multi-stage intrusions against Brazilian financial institutions, putting Pix transfers and cryptocurrency custody secrets a...
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor Meta
H score30
First: 01.09.2026 20:19
Last: 01.09.2026 20:19
Sources 1
How related:
The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that's infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.
About this happening:
Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor MetaHow related: The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that's infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.
About this happening: Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...
Breeze Comet Brazilian payment-system fraud campaign
Campaign
H score32
First: 01.09.2026 20:19
Last: 01.09.2026 20:19
Sources 1
About this happening:
Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...
Breeze Comet Brazilian payment-system fraud campaign
CampaignAbout this happening: Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...
Triad Nexus investment scam and brand impersonation campaign targeting emerging markets
Campaign
H score33
First: 14.04.2026 15:00
Last: 14.04.2026 15:00
Sources 1
About this happening:
The Triad Nexus campaign is continuing to run large-scale investment scams and brand impersonation, expanding into emerging markets and driving higher fraud losses...
Triad Nexus investment scam and brand impersonation campaign targeting emerging markets
CampaignAbout this happening: The Triad Nexus campaign is continuing to run large-scale investment scams and brand impersonation, expanding into emerging markets and driving higher fraud losses...
Timeline
-
08.09.2026 19:20 2 articles · 17h ago
Breeze Comet abuses Brazilian payment infrastructure for illegal transactions
Campaign Scope UpdateBreeze Comet, also tracked as CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064, is infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain; Google Threat Intelligence Group (GTIG) and Mandiant say the group's earliest attacks date back to 2024, and it has also used insecure Brazilian government websites to stage malware for follow-on social engineering while extending the same pattern to municipal websites in Nigeria, Paraguay, Ghana, and Venezuela.
Show sources
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution — thehackernews.com — 08.09.2026 19:20
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution — thehackernews.com — 08.09.2026 19:20