gcp Google Cloud Blog ·

Google Threat Intelligence Details Financially Motivated Threat Actor BREEZE COMET

blogsecuritysecurity-advisoryarchitectfinanceretailgovernmentenergy
security announcement

Google's Mandiant and Threat Intelligence Group detail the operations of BREEZE COMET, a financially motivated threat actor. This group specializes in manipulating payment systems and banking software in Brazil and has evolved to use custom malware suites, compromised trusted websites, and generative AI for development. BREEZE COMET primarily targets Brazilian financial services, retail, and eCommerce organizations, including banks, payment processors, and fintech providers. Their sophisticated tactics involve exploiting CI/CD environments, stealing mTLS credentials, and deploying bespoke routing malware like COBALTSPIN and backdoors like LIGHTPAINT.

  • Financially Motivated Threat Actor BREEZE COMET Detailed
  • BREEZE COMET Targets Brazilian Financial Systems
  • Initial Access and Foothold Establishment
  • Privilege Escalation and Internal Reconnaissance
  • Lateral Movement and Network Tunneling
Security (6)
  • Financially Motivated Threat Actor BREEZE COMET Detailed

    Google Threat Intelligence Group (GTIG) and Mandiant detail BREEZE COMET (formerly UNC5669), a financially motivated actor targeting Brazilian payment systems and banking software. The group's tactics have evolved to leverage custom malware, compromised websites, and generative AI for development.

  • BREEZE COMET Targets Brazilian Financial Systems

    The threat actor focuses on organizations with permission to conduct transactions through banking software and APIs like Pix, STR, and Boleto, requiring access to the National Financial System Network and mTLS credentials. They seek persistent access to Active Directory and cloud environments.

  • Initial Access and Foothold Establishment

    BREEZE COMET uses methods like password spraying, voice phishing, and compromised Brazilian government websites to deliver RMM tools and infostealers. They also connect rogue hardware directly into retail networks and exploit vulnerabilities in JBoss AS servers.

  • Privilege Escalation and Internal Reconnaissance

    The group deploys public utilities like Impacket and ADRecon, alongside custom LDAP brute-forcing tools, often targeting CI/CD environments to steal pipeline credentials, API keys, and cloud access tokens. They also search for mTLS credentials and administrative certificates.

  • Lateral Movement and Network Tunneling

    BREEZE COMET abuses standard protocols like RDP and SMB with hijacked service accounts. They deploy COBALTSPIN, a custom Rust-based routing malware, to establish a reverse SOCKS5 proxy over WebSocket, facilitating secure lateral movement through segmented financial networks.

  • Maintaining Presence via Bespoke C2 Frameworks

    After initially relying on commercial RMM tools, BREEZE COMET now deploys malicious Kubernetes pods for persistence and steals cloud secrets. They also developed custom Java-based backdoors like LIGHTPAINT for VPN installation and MILDFROST for covert DNS tunneling.

Read the original announcement →

https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/

Related releases