BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite — Threadlinqs Intelligence
As of 2026-09-02, BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite is a critical-severity apt threat attributed to BREEZE COMET (formerly UNC5669, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-2266 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Updated: 2026-09-02 · revalidated 1× · latest source
Attribution: BREEZE COMET (formerly UNC5669 · FINANCIAL
Google Threat Intelligence Group (GTIG) and Mandiant document BREEZE COMET (formerly UNC5669 / Plump Spider), a financially motivated actor that evolved from opportunistic Brazilian retail banking
BREEZE COMET, tracked since at least September 2023 by CrowdStrike as PLUMP SPIDER (community ID SHADOW-AETHER-064) and since 2024 by Mandiant as UNC5669, is a financially motivated cybercriminal syndicate that has shifted its targeting from opportunistic, client-side Brazilian retail-banking fraud toward direct, hands-on-keyboard intrusions into the core systems that process Brazil's national instant-payment rails: Pix, the STR interbank transfer system, and Boleto billing, reached via the RSFN national financial-sector network and mTLS-authenticated payment APIs.
Initial access has evolved from 2024-era password spraying and voice-phishing (vishing) calls that impersonate IT support to convince staff to install remote monitoring and management (RMM) tools such as AnyDesk, to 2025-era techniques including rogue physical hardware implants inserted directly into retail store networks to gain a lateral-movement foothold, exploitation of JBoss Application Server vulnerabilities (specific CVE not disclosed by researchers), and attempted insider recruitment (corroborated by Axur). From mid-2025 the group began staging payloads and command-and-control on compromised Brazilian municipal government websites, which bypasses network domain-reputation filtering; the same technique has since been replicated on government domains in Nigeria, Guinea, Paraguay, and Venezuela, signaling geographic expansion beyond Brazil.
The group's 2025-2026 toolset is a custom, redundant, multi-language backdoor suite: COBALTSPIN (Rust) is a lightweight tunneler that opens a reverse SOCKS5 proxy over WebSocket to bridge C2 traffic into segmented financial networks; REALBREEZE is a custom LDAP brute-forcing utility used for Active Directory and cloud credential validation; LIGHTPAINT (Java) installs and silently persists a SoftEther VPN client, opening inbound Windows Defender Firewall rules and clearing 'Windows Networking Vpn Plugin Platform' event logs to erase forensic evidence; MILDFROST is a passive Java JAR backdoor that hides in JVM process space and falls back to a slow, covert DNS tunnel (via a class named DnsCommandBeacon) to fetch fresh native payloads; KICKPLATE (Nim) impersonates Windows Update Health Tools, abuses scheduled tasks (schtasks.exe as SYSTEM) and registry run keys, and modifies Windows services and startup .lnk shortcuts for persistence; BOATBEAM (Go) runs a fake IIS HTTPS listener on port 443 that only activates C2 functionality when it receives a specific session cookie, giving the actor a redundant, low-visibility channel. XWORM, a widely available commercial/cracked RAT, is used as an initial-access payload disguised as tax/receipt documents (e.g. ComprovantePDF.exe) staged on the compromised government sites.
Once inside, the actor uses Impacket, ADRecon, ADVipscan, and AI-assisted custom reconnaissance scripts to enumerate SMB pathways, hijack service accounts for RDP and SMB lateral movement, and search hosts and environment variables for terms such as boleto, cnab, remessa, and webhook/instant-payment references, hunting for mTLS credentials, administrative certificates, CI/CD pipeline credentials, cloud access tokens, and Kubernetes secrets (exfiltrated via the public paste site dontpad.com). Mandiant identified direct evidence that large language models accelerated development of the actor's reconnaissance, credential-validation, mass-deployment, and data-extraction scripts: the AI-authored code is described as highly functional but lacking human idiosyncrasies, heavily reliant on unrolled logic, verbose explanatory comments, and standardized execution headers.
Once access to financial-switch/payment infrastructure is achieved, the actor executes two waves of hundreds of fraudulent transactions within 24-48 hours, with at least one confirmed heist netting tens of thousands of USD, before clearing event logs and deleting compromise artifacts. GTIG/Mandiant assess BREEZE COMET represents a template for future financial
Target sectors: financial services, banking, payment processors, fintech, retail, government administration
Target regions: brazil, nigeria, guinea, paraguay, venezuela
Timeline
- CrowdStrike first tracks a Brazil-based eCrime adversary, PLUMP SPIDER (community ID SHADOW-AETHER-064), later attributed by Mandiant as UNC5669 / BREEZE COMET.
- Actor conducts opportunistic Brazilian retail banking fraud via password spraying and vishing calls that trick staff into installing the AnyDesk RMM tool for initial access.
- Actor begins inserting rogue physical hardware implants directly into retail store networks to establish footholds for lateral movement.
- Actor begins staging payloads and command-and-control infrastructure on compromised Brazilian municipal government websites to bypass network domain-reputation filtering.
- The compromised-government-website staging technique is replicated on government domains in Nigeria (mrtb.gov.ng), Guinea (credeb.gov.gn), Paraguay (jmcov.gov.py), and Venezuela (sit.baer.gob.ve).
- Axur reports BREEZE COMET/Plump Spider expanding beyond banking institutions to insurance companies, retail businesses, and point-of-sale system providers.
- Axur publishes updated modus-operandi reporting detailing insider-recruitment offers to managers, IT staff, and VPN-privileged employees, including an 80-minute vishing call in which operators posed as IT support and requested screenshots to build credibility.
- Actor shifts from commercial RMM tools to a custom, redundant multi-language backdoor suite (COBALTSPIN, REALBREEZE, LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM) alongside XWORM, enabling direct intrusions into core financial-switch infrastructure.
- Mandiant identifies direct evidence that large language models accelerated the actor's development of reconnaissance, credential-validation, mass-deployment, and data-extraction scripts.
- Actor achieves access to core financial-switch/instant-payment infrastructure and executes two waves of hundreds of fraudulent transactions within 24-48 hours, netting tens of thousands of USD in at least one confirmed heist.
- Google Threat Intelligence Group and Mandiant publish the public BREEZE COMET threat actor profile, renaming UNC5669/Plump Spider.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
APT, CRITICAL, threat intelligence, cybersecurity, T1190, T1566.004, T1204.002, T1547.001, T1547.009, T1053.005, T1543.003, T1685, T1685.005, T1036