Essential Insights
- BREEZE COMET exploits compromised government websites and uses custom malware and AI-assisted tools to gain initial access, persist, and exfiltrate data across Brazilian financial networks.
- The threat actor utilizes stolen credentials, low-visibility reconnaissance, and lateral movement techniques like SMB, RDP, and evasive tunneling malware (COBALTSPIN) to navigate and manipulate internal financial systems.
- BREEZE COMET targets payment APIs, banking software, and cloud environments, aiming to conduct fraudulent transfers, steal sensitive credentials, and escalate privileges in core banking environments.
Threat, Attack Techniques, and Targets
The threat, known as BREEZE COMET, has been active in 2024 targeting Brazilian financial organizations. It primarily aims to manipulate payment systems and banking software. BREEZE COMET usually targets banks, payment processors, retailers, exchanges, and fintech companies. These organizations have permission to conduct financial transactions, making them valuable targets.
BREEZE COMET uses various methods to gain access. It employs password spraying and voice phishing calls impersonating IT support. The attackers also use compromised Brazilian small government websites to stage malware and leverage trusted infrastructure to avoid detection. They often deploy Remote Monitoring and Management (RMM) tools and backdoors like XWORM on compromised systems. The actors also exploit vulnerabilities in JBoss AS servers and connect rogue hardware devices to store networks for access.
Once inside, BREEZE COMET escalates privileges and performs internal reconnaissance. It uses tools like Impacket, ADRecon, and custom utilities to search for credentials and sensitive data. The group specifically targets development and cloud environments to steal cloud access tokens and API keys. They look for mTLS credentials and administrative certificates that can help access core banking systems. After gathering information, they move laterally through the network using hijacked service accounts and specialized malware.
Impact, Security Implications, and Remediation Guidance
BREEZE COMET’s activities could cause serious disruption. They could steal money by conducting fraudulent transfers. The attackers’ ability to compromise payment systems and internal networks poses a high security risk. If successful, they could affect financial stability and customer trust.
The malware and tactics used by BREEZE COMET show the importance of strong security measures. Organizations should protect their network credentials, monitor for unusual activity, and secure remote access. Compromised trusted websites are a key part of their strategy, so web security must be a priority. Detecting tools like Impacket, ADRecon, and custom malware is also crucial.
If you suspect an attack, it is best to consult with your security vendor or relevant authorities for specific guidance. They can provide tailored remediation steps and assistance. Overall, organizations need to strengthen defenses around sensitive systems and consider advanced monitoring to detect suspicious activity early.
Expand Your Tech Knowledge
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Stay inspired by the vast knowledge available on Wikipedia.
ThreatIntel-V1
