Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure
Campaign
Summary
Hide ▲
Show ▼
The Slim Spider campaign is tied to multi-stage intrusions against Brazilian financial institutions, putting Pix transfers and cryptocurrency custody secrets at risk of theft and unauthorized access. CrowdStrike says the Brazil-based cluster has operated since at least March 2026 and shows deep knowledge of financial cloud environments. The activity uses custom Bash scripts to steal temporary cloud credentials, enumerate secrets, and pivot into Azure DevOps and managed Kubernetes infrastructure. Supporting tools and panels point to an organized operation built for credential abuse, endpoint discovery, and bulk unauthorized financial transactions.
Related Happenings
Breeze Comet-CL-CRI-1163-Plump Spider alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score35
First: 08.09.2026 19:20
Last: 08.09.2026 19:20
Sources 1
How related:
While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, Breeze Comet's campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region.
About this happening:
Breeze Comet is pushing Latin American cybercrime away from client-side retail fraud and toward direct intrusions into payment infrastructure, increasing risk to Bra...
Breeze Comet-CL-CRI-1163-Plump Spider alliance reshapes ransomware ecosystem operations
Threat Actor MetaHow related: While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, Breeze Comet's campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region.
About this happening: Breeze Comet is pushing Latin American cybercrime away from client-side retail fraud and toward direct intrusions into payment infrastructure, increasing risk to Bra...
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor Meta
H score30
First: 01.09.2026 20:19
Last: 01.09.2026 20:19
Sources 1
How related:
The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that's infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.
About this happening:
Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...
Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization
Threat Actor MetaHow related: The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that's infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.
About this happening: Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...
Breeze Comet Brazilian payment-system fraud campaign
Campaign
H score32
First: 01.09.2026 20:19
Last: 01.09.2026 20:19
Sources 1
About this happening:
Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...
Breeze Comet Brazilian payment-system fraud campaign
CampaignAbout this happening: Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
UNC6671 diversifies extortion operations across multiple public brands
Threat Actor Meta
H score44
First: 06.08.2026 23:07
Last: 06.08.2026 23:07
Sources 1
About this happening:
UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...
UNC6671 diversifies extortion operations across multiple public brands
Threat Actor MetaAbout this happening: UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...
Timeline
-
08.09.2026 19:20 2 articles · 17h ago
Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure
Initial DisclosureThe first stage focuses on cloud footholds: scripts query instance metadata, steal temporary credentials, and enumerate secrets from the cloud credential manager. That access then enables later pivots into DevOps and Kubernetes environments.
Show sources
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution — thehackernews.com — 08.09.2026 19:20
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution — thehackernews.com — 08.09.2026 19:20