Find notable cyber news and cases, enriched with sources, timelines, and signals.

Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The Slim Spider campaign is tied to multi-stage intrusions against Brazilian financial institutions, putting Pix transfers and cryptocurrency custody secrets at risk of theft and unauthorized access. CrowdStrike says the Brazil-based cluster has operated since at least March 2026 and shows deep knowledge of financial cloud environments. The activity uses custom Bash scripts to steal temporary cloud credentials, enumerate secrets, and pivot into Azure DevOps and managed Kubernetes infrastructure. Supporting tools and panels point to an organized operation built for credential abuse, endpoint discovery, and bulk unauthorized financial transactions.

Related Happenings

Breeze Comet-CL-CRI-1163-Plump Spider alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score35 First: 08.09.2026 19:20 Last: 08.09.2026 19:20 Sources 1

How related: While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, Breeze Comet's campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region.

About this happening: Breeze Comet is pushing Latin American cybercrime away from client-side retail fraud and toward direct intrusions into payment infrastructure, increasing risk to Bra...

Breeze Comet Brazil-based e-crime cluster with alias overlap and payment-fraud monetization

Threat Actor Meta
H score30 First: 01.09.2026 20:19 Last: 01.09.2026 20:19 Sources 1

How related: The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that's infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.

About this happening: Breeze Comet is now linked to a separate Brazil-focused payment-fraud track, while Slim Spider is a Brazil-based financially motivated cluster active since at least ...

Breeze Comet Brazilian payment-system fraud campaign

Campaign
H score32 First: 01.09.2026 20:19 Last: 01.09.2026 20:19 Sources 1

About this happening: Breeze Comet has been conducting a financial intrusion campaign against Brazilian financial services, retail, and e-commerce organizations since 2024, putting paym...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

UNC6671 diversifies extortion operations across multiple public brands

Threat Actor Meta
H score44 First: 06.08.2026 23:07 Last: 06.08.2026 23:07 Sources 1

About this happening: UNC6671 has shifted to a multi-brand extortion model, widening its operating footprint across Redact, Pink, Helix, and Falcon and increasing the difficulty of tracking...

Timeline

  1. 08.09.2026 19:20 2 articles · 17h ago

    Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure

    Initial Disclosure

    The first stage focuses on cloud footholds: scripts query instance metadata, steal temporary credentials, and enumerate secrets from the cloud credential manager. That access then enables later pivots into DevOps and Kubernetes environments.

    Show sources