Fast Facts
- Breeze Comet employs sophisticated attacks such as password spraying, impersonation via voice calls, and deployment of web shells on vulnerable servers to access and manipulate payment systems in Brazil.
- The group uses advanced malware and backdoors (e.g., COBALTSPIN, LIGHTPAINT, MILDFROST) alongside compromised websites and cloud secrets to establish persistent, covert access to financial infrastructure.
- Their operations culminate in executing fraudulent transactions through core financial applications, facilitated by stolen credentials, with efforts to erase traces and evade detection, heightening risks to regional financial stability.
Threat Overview, Techniques, and Targets
The threat actor known as Breeze Comet primarily targets Brazilian financial services, retail, and e-commerce organizations. Since 2024, they have been focused on manipulating payment systems and banking software. They aim to access systems used for financial transactions, such as Pix, STR, and Boleto.
The attackers gain initial access through different methods. They use password spraying and impersonate IT support staff during voice calls to persuade targets to install Remote Monitoring and Management (RMM) tools like AnyDesk. They also target vulnerable JBoss AS servers to deploy web shells, which then deliver tools such as Chisel and proxy utilities.
Once inside, Breeze Comet moves laterally within networks by connecting rogue hardware devices, infecting government websites, and using reconnaissance tools like Impacket and LDAP brute-forcing utilities. They deploy malware such as COBALTSPIN, a network tunneler, and multiple backdoors including LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM for persistent access.
Their goal is to access necessary accounts, gain sensitive credentials, and understand financial processing procedures. They then use compromised privileged accounts to execute hundreds of fraudulent transactions while deleting logs and files to hide tracks.
Impact, Security Concerns, and Remediation
Breeze Comet’s activities pose serious risks to financial organizations. They can carry out large-scale fraudulent transactions, resulting in significant monetary losses. Their tactics bypass traditional defenses by using custom malware, compromised websites, and lateral movement techniques. This increases the threat of extended network compromise and data theft.
The security implications include potential disruption of financial operations and loss of trust from customers. Attackers may expand their infrastructure into other Latin American and African countries, raising regional threats.
Due to the complexity and evolving tactics used by Breeze Comet, remediation guidance should be obtained from relevant vendors or authorities. Organizations should review their systems for vulnerabilities, monitor for suspicious activity, and strengthen access controls. It is recommended to consult cybersecurity experts or vendor resources for detailed cleanup and security measures.
Expand Your Tech Knowledge
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
