BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite

BREEZE COMET (ex-UNC5669) Targets Brazilian Financial (TL-2026-2266) is a critical-severity advanced persistent threat campaign, first published 2026-09-01 and last reviewed 2026-09-02. It is attributed to BREEZE COMET with high confidence, affects Red Hat JBoss Application Server, maps to 30 MITRE ATT&CK techniques (T1018, T1021.001, T1021.002), and is covered by 9 detection rules and 32 indicators of compromise.

Key facts for TL-2026-2266

Threat ID
TL-2026-2266
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-09-01
Last reviewed
2026-09-02
Attribution
BREEZE COMET
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
financial services, banking, payment processors, fintech, retail, government administration
Target regions
brazil, nigeria, guinea, paraguay, venezuela
Detection rules
9
Indicators of compromise
32
Updates
2026-09-02 · revalidated 1× · latest source

Malware and tooling in BREEZE COMET (ex-UNC5669) Targets Brazilian Financial

Malware and tooling: BOATBEAM, COBALTSPIN, KICKPLATE, LIGHTPAINT, MILDFROST, REALBREEZE, XWorm

Google Threat Intelligence Group (GTIG) and Mandiant document BREEZE COMET (formerly UNC5669 / Plump Spider), a financially motivated actor that evolved from opportunistic Brazilian retail banking fraud into direct intrusions of core financial-switch and instant-payment (Pix/STR/Boleto) infrastructure. The group deploys a custom multi-language backdoor suite and shows evidence of generative-AI-accelerated malware and script development, with a confirmed heist of tens of thousands of USD and hundreds of fraudulent transactions within 24-48 hours of access.

How BREEZE COMET (ex-UNC5669) Targets Brazilian Financial works

BREEZE COMET, tracked since at least September 2023 by CrowdStrike as PLUMP SPIDER (community ID SHADOW-AETHER-064) and since 2024 by Mandiant as UNC5669, is a financially motivated cybercriminal syndicate that has shifted its targeting from opportunistic, client-side Brazilian retail-banking fraud toward direct, hands-on-keyboard intrusions into the core systems that process Brazil's national instant-payment rails: Pix, the STR interbank transfer system, and Boleto billing, reached via the RSFN national financial-sector network and mTLS-authenticated payment APIs.

Initial access has evolved from 2024-era password spraying and voice-phishing (vishing) calls that impersonate IT support to convince staff to install remote monitoring and management (RMM) tools such as AnyDesk, to 2025-era techniques including rogue physical hardware implants inserted directly into retail store networks to gain a lateral-movement foothold, exploitation of JBoss Application Server vulnerabilities (specific CVE not disclosed by researchers), and attempted insider recruitment (corroborated by Axur). From mid-2025 the group began staging payloads and command-and-control on compromised Brazilian municipal government websites, which bypasses network domain-reputation filtering; the same technique has since been replicated on government domains in Nigeria, Guinea, Paraguay, and Venezuela, signaling geographic expansion beyond Brazil.

The group's 2025-2026 toolset is a custom, redundant, multi-language backdoor suite: COBALTSPIN (Rust) is a lightweight tunneler that opens a reverse SOCKS5 proxy over WebSocket to bridge C2 traffic into segmented financial networks; REALBREEZE is a custom LDAP brute-forcing utility used for Active Directory and cloud credential validation; LIGHTPAINT (Java) installs and silently persists a SoftEther VPN client, opening inbound Windows Defender Firewall rules and clearing 'Windows Networking Vpn Plugin Platform' event logs to erase forensic evidence; MILDFROST is a passive Java JAR backdoor that hides in JVM process space and falls back to a slow, covert DNS tunnel (via a class named DnsCommandBeacon) to fetch fresh native payloads; KICKPLATE (Nim) impersonates Windows Update Health Tools, abuses scheduled tasks (schtasks.exe as SYSTEM) and registry run keys, and modifies Windows services and startup .lnk shortcuts for persistence; BOATBEAM (Go) runs a fake IIS HTTPS listener on port 443 that only activates C2 functionality when it receives a specific session cookie, giving the actor a redundant, low-visibility channel. XWORM, a widely available commercial/cracked RAT, is used as an initial-access payload disguised as tax/receipt documents (e.g. ComprovantePDF.exe) staged on the compromised government sites.

Once inside, the actor uses Impacket, ADRecon, ADVipscan, and AI-assisted custom reconnaissance scripts to enumerate SMB pathways, hijack service accounts for RDP and SMB lateral movement, and search hosts and environment variables for terms such as boleto, cnab, remessa, and webhook/instant-payment references, hunting for mTLS credentials, administrative certificates, CI/CD pipeline credentials, cloud access tokens, and Kubernetes secrets (exfiltrated via the public paste site dontpad.com). Mandiant identified direct evidence that large language models accelerated development of the actor's reconnaissance, credential-validation, mass-deployment, and data-extraction scripts: the AI-authored code is described as highly functional but lacking human idiosyncrasies, heavily reliant on unrolled logic, verbose explanatory comments, and standardized execution headers.

Once access to financial-switch/payment infrastructure is achieved, the actor executes two waves of hundreds of fraudulent transactions within 24-48 hours, with at least one confirmed heist netting tens of thousands of USD, before clearing event logs and deleting compromise artifacts. GTIG/Mandiant assess BREEZE COMET represents a template for future financially motivated threats against Latin American financial infrastructure and a shift from high-volume client-side retail fraud toward direct compromise of core financial-switch systems.

MITRE ATT&CK techniques used in TL-2026-2266

Discovery

T1018 Remote System Discovery; T1087 Account Discovery; T1087.002 Account Discovery: Domain Account

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares

Defense Evasion

T1036 Masquerading; T1036.005 Masquerading: Match Legitimate Name or Location; T1070.001 Indicator Removal: Clear Windows Event Logs; T1562.001 Impair Defenses: Disable or Modify Tools; T1610 Deploy Container

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1543.003 Create or Modify System Process: Windows Service; T1547.001 Registry Run Keys / Startup Folder; T1547.009 Boot or Logon Autostart Execution: Shortcut Modification

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1071.004 Application Layer Protocol: DNS; T1219 Remote Access Tools; T1572 Protocol Tunneling

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1200 Hardware Additions; T1566.004 Phishing: Spearphishing Voice

Credential Access

T1110 Brute Force; T1110.003 Brute Force: Password Spraying; T1552.001 Unsecured Credentials: Credentials In Files

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs

Affected products and versions in BREEZE COMET (ex-UNC5669) Targets Brazilian Financial

  • Red Hat — JBoss Application Server
    Vulnerable versions: not disclosed in public reporting
  • Microsoft — Windows (endpoints and servers)
    Vulnerable versions: all supported versions targeted via registry run keys, scheduled tasks, Windows services, and Defender Firewall/real-time monitoring tampering

Remediation for BREEZE COMET (ex-UNC5669) Targets Brazilian Financial

Patches

  • Patch and harden internet-facing JBoss Application Server deployments; researchers did not disclose specific exploited CVEs, so audit for any outdated/unpatched JBoss AS instances

Immediate actions

  • Deploy 802.1X network access control on physical switch ports, disable unused ports, and enforce MAC limiting to block rogue hardware implants
  • Block execution from user-writable directories and mount /tmp and /home with noexec
  • Segment networks to block SMB (445) and RDP (3389) between workstation and server VLANs
  • Alert on and restrict unauthorized/portable RMM tool execution (e.g. AnyDesk) and block unapproved system service/daemon registrations

Workarounds

  • Restrict administrative utilities such as ntdsutil.exe and vssadmin.exe to authorized admin workstations
  • Block egress to non-essential ports/protocols and to public paste sites such as dontpad.com; apply SSL/TLS decryption and DPI to outbound traffic

Longer-term hardening

  • Enforce PowerShell Constrained Language Mode and enable Script Block Logging (Event ID 4104)
  • Move mTLS certificates and administrative credentials into a centralized secrets manager (e.g. HashiCorp Vault) behind dedicated PAM jump hosts
  • Mandate phishing-resistant MFA on all external portals, RMM tools, and VPN access points
  • Apply Kubernetes RBAC least privilege, Pod Security Admission, and dynamic admission controllers (OPA Gatekeeper/Kyverno) to prevent CI/CD and cloud secret exfiltration

Timeline of BREEZE COMET (ex-UNC5669) Targets Brazilian Financial

  • CrowdStrike first tracks a Brazil-based eCrime adversary, PLUMP SPIDER (community ID SHADOW-AETHER-064), later attributed by Mandiant as UNC5669 / BREEZE COMET.
  • Actor conducts opportunistic Brazilian retail banking fraud via password spraying and vishing calls that trick staff into installing the AnyDesk RMM tool for initial access.
  • Actor begins inserting rogue physical hardware implants directly into retail store networks to establish footholds for lateral movement.
  • The compromised-government-website staging technique is replicated on government domains in Nigeria (mrtb.gov.ng), Guinea (credeb.gov.gn), Paraguay (jmcov.gov.py), and Venezuela (sit.baer.gob.ve).
  • Actor begins staging payloads and command-and-control infrastructure on compromised Brazilian municipal government websites to bypass network domain-reputation filtering.
  • Axur reports BREEZE COMET/Plump Spider expanding beyond banking institutions to insurance companies, retail businesses, and point-of-sale system providers.
  • Axur publishes updated modus-operandi reporting detailing insider-recruitment offers to managers, IT staff, and VPN-privileged employees, including an 80-minute vishing call in which operators posed as IT support and requested screenshots to build credibility.
  • Mandiant identifies direct evidence that large language models accelerated the actor's development of reconnaissance, credential-validation, mass-deployment, and data-extraction scripts.
  • Actor shifts from commercial RMM tools to a custom, redundant multi-language backdoor suite (COBALTSPIN, REALBREEZE, LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM) alongside XWORM, enabling direct intrusions into core financial-switch infrastructure.
  • Google Threat Intelligence Group and Mandiant publish the public BREEZE COMET threat actor profile, renaming UNC5669/Plump Spider.
  • Actor achieves access to core financial-switch/instant-payment infrastructure and executes two waves of hundreds of fraudulent transactions within 24-48 hours, netting tens of thousands of USD in at least one confirmed heist.

Update history for TL-2026-2266

Sources cited for BREEZE COMET (ex-UNC5669) Targets Brazilian Financial

More in apt

Detection coverage for TL-2026-2266

As of 2026-09-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2266 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2266

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats