Find notable cyber news and cases, enriched with sources, timelines, and signals.

Breeze Comet-CL-CRI-1163-Plump Spider alliance reshapes ransomware ecosystem operations

Threat Actor Meta
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

Breeze Comet is pushing Latin American cybercrime away from client-side retail fraud and toward direct intrusions into payment infrastructure, increasing risk to Brazilian financial systems and instant-transfer rails. The group's activity has expanded beyond Brazil to municipal websites in other countries, creating a reusable path for fraudulent transactions and follow-on social engineering.

Related Happenings

Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure

Campaign
H score34 First: 08.09.2026 19:20 Last: 08.09.2026 19:20 Sources 1

How related: A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.

About this happening: The Slim Spider campaign is tied to multi-stage intrusions against Brazilian financial institutions, putting Pix transfers and cryptocurrency custody secrets a...

Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization

Threat Actor Meta
H score30 First: 01.09.2026 20:19 Last: 01.09.2026 20:19 Sources 1

How related: The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that's infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.

About this happening: Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...

Breeze Comet Brazilian payment-system fraud campaign

Campaign
H score32 First: 01.09.2026 20:19 Last: 01.09.2026 20:19 Sources 1

About this happening: Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...

Triad Nexus investment scam and brand impersonation campaign targeting emerging markets

Campaign
H score33 First: 14.04.2026 15:00 Last: 14.04.2026 15:00 Sources 1

About this happening: The Triad Nexus campaign is continuing to run large-scale investment scams and brand impersonation, expanding into emerging markets and driving higher fraud losses...

Timeline

  1. 08.09.2026 19:20 2 articles · 17h ago

    Breeze Comet abuses Brazilian payment infrastructure for illegal transactions

    Campaign Scope Update

    Breeze Comet, also tracked as CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064, is infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain; Google Threat Intelligence Group (GTIG) and Mandiant say the group's earliest attacks date back to 2024, and it has also used insecure Brazilian government websites to stage malware for follow-on social engineering while extending the same pattern to municipal websites in Nigeria, Paraguay, Ghana, and Venezuela.

    Show sources