BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite
BREEZE COMET (ex-UNC5669) Targets Brazilian Financial (TL-2026-2266) is a critical-severity advanced persistent threat campaign, first published 2026-09-01 and last reviewed 2026-09-02. It is attributed to BREEZE COMET with high confidence, affects Red Hat JBoss Application Server, maps to 30 MITRE ATT&CK techniques (T1018, T1021.001, T1021.002), and is covered by 9 detection rules and 32 indicators of compromise.
Key facts for TL-2026-2266
- Threat ID
- TL-2026-2266
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-09-01
- Last reviewed
- 2026-09-02
- Attribution
- BREEZE COMET
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, payment processors, fintech, retail, government administration
- Target regions
- brazil, nigeria, guinea, paraguay, venezuela
- Detection rules
- 9
- Indicators of compromise
- 32
- Updates
- 2026-09-02 · revalidated 1× · latest source
Malware and tooling in BREEZE COMET (ex-UNC5669) Targets Brazilian Financial
Malware and tooling: BOATBEAM, COBALTSPIN, KICKPLATE, LIGHTPAINT, MILDFROST, REALBREEZE, XWorm
Google Threat Intelligence Group (GTIG) and Mandiant document BREEZE COMET (formerly UNC5669 / Plump Spider), a financially motivated actor that evolved from opportunistic Brazilian retail banking fraud into direct intrusions of core financial-switch and instant-payment (Pix/STR/Boleto) infrastructure. The group deploys a custom multi-language backdoor suite and shows evidence of generative-AI-accelerated malware and script development, with a confirmed heist of tens of thousands of USD and hundreds of fraudulent transactions within 24-48 hours of access.
How BREEZE COMET (ex-UNC5669) Targets Brazilian Financial works
BREEZE COMET, tracked since at least September 2023 by CrowdStrike as PLUMP SPIDER (community ID SHADOW-AETHER-064) and since 2024 by Mandiant as UNC5669, is a financially motivated cybercriminal syndicate that has shifted its targeting from opportunistic, client-side Brazilian retail-banking fraud toward direct, hands-on-keyboard intrusions into the core systems that process Brazil's national instant-payment rails: Pix, the STR interbank transfer system, and Boleto billing, reached via the RSFN national financial-sector network and mTLS-authenticated payment APIs.
Initial access has evolved from 2024-era password spraying and voice-phishing (vishing) calls that impersonate IT support to convince staff to install remote monitoring and management (RMM) tools such as AnyDesk, to 2025-era techniques including rogue physical hardware implants inserted directly into retail store networks to gain a lateral-movement foothold, exploitation of JBoss Application Server vulnerabilities (specific CVE not disclosed by researchers), and attempted insider recruitment (corroborated by Axur). From mid-2025 the group began staging payloads and command-and-control on compromised Brazilian municipal government websites, which bypasses network domain-reputation filtering; the same technique has since been replicated on government domains in Nigeria, Guinea, Paraguay, and Venezuela, signaling geographic expansion beyond Brazil.
The group's 2025-2026 toolset is a custom, redundant, multi-language backdoor suite: COBALTSPIN (Rust) is a lightweight tunneler that opens a reverse SOCKS5 proxy over WebSocket to bridge C2 traffic into segmented financial networks; REALBREEZE is a custom LDAP brute-forcing utility used for Active Directory and cloud credential validation; LIGHTPAINT (Java) installs and silently persists a SoftEther VPN client, opening inbound Windows Defender Firewall rules and clearing 'Windows Networking Vpn Plugin Platform' event logs to erase forensic evidence; MILDFROST is a passive Java JAR backdoor that hides in JVM process space and falls back to a slow, covert DNS tunnel (via a class named DnsCommandBeacon) to fetch fresh native payloads; KICKPLATE (Nim) impersonates Windows Update Health Tools, abuses scheduled tasks (schtasks.exe as SYSTEM) and registry run keys, and modifies Windows services and startup .lnk shortcuts for persistence; BOATBEAM (Go) runs a fake IIS HTTPS listener on port 443 that only activates C2 functionality when it receives a specific session cookie, giving the actor a redundant, low-visibility channel. XWORM, a widely available commercial/cracked RAT, is used as an initial-access payload disguised as tax/receipt documents (e.g. ComprovantePDF.exe) staged on the compromised government sites.
Once inside, the actor uses Impacket, ADRecon, ADVipscan, and AI-assisted custom reconnaissance scripts to enumerate SMB pathways, hijack service accounts for RDP and SMB lateral movement, and search hosts and environment variables for terms such as boleto, cnab, remessa, and webhook/instant-payment references, hunting for mTLS credentials, administrative certificates, CI/CD pipeline credentials, cloud access tokens, and Kubernetes secrets (exfiltrated via the public paste site dontpad.com). Mandiant identified direct evidence that large language models accelerated development of the actor's reconnaissance, credential-validation, mass-deployment, and data-extraction scripts: the AI-authored code is described as highly functional but lacking human idiosyncrasies, heavily reliant on unrolled logic, verbose explanatory comments, and standardized execution headers.
Once access to financial-switch/payment infrastructure is achieved, the actor executes two waves of hundreds of fraudulent transactions within 24-48 hours, with at least one confirmed heist netting tens of thousands of USD, before clearing event logs and deleting compromise artifacts. GTIG/Mandiant assess BREEZE COMET represents a template for future financially motivated threats against Latin American financial infrastructure and a shift from high-volume client-side retail fraud toward direct compromise of core financial-switch systems.
MITRE ATT&CK techniques used in TL-2026-2266
Discovery
T1018 Remote System Discovery; T1087 Account Discovery; T1087.002 Account Discovery: Domain Account
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares
Defense Evasion
T1036 Masquerading; T1036.005 Masquerading: Match Legitimate Name or Location; T1070.001 Indicator Removal: Clear Windows Event Logs; T1562.001 Impair Defenses: Disable or Modify Tools; T1610 Deploy Container
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1543.003 Create or Modify System Process: Windows Service; T1547.001 Registry Run Keys / Startup Folder; T1547.009 Boot or Logon Autostart Execution: Shortcut Modification
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1071.004 Application Layer Protocol: DNS; T1219 Remote Access Tools; T1572 Protocol Tunneling
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application; T1200 Hardware Additions; T1566.004 Phishing: Spearphishing Voice
Credential Access
T1110 Brute Force; T1110.003 Brute Force: Password Spraying; T1552.001 Unsecured Credentials: Credentials In Files
Impact
defense-impairment
T1685 Disable or Modify Tools; T1685.005 Clear Windows Event Logs
Affected products and versions in BREEZE COMET (ex-UNC5669) Targets Brazilian Financial
- Red Hat — JBoss Application Server
Vulnerable versions: not disclosed in public reporting - Microsoft — Windows (endpoints and servers)
Vulnerable versions: all supported versions targeted via registry run keys, scheduled tasks, Windows services, and Defender Firewall/real-time monitoring tampering
Remediation for BREEZE COMET (ex-UNC5669) Targets Brazilian Financial
Patches
- Patch and harden internet-facing JBoss Application Server deployments; researchers did not disclose specific exploited CVEs, so audit for any outdated/unpatched JBoss AS instances
Immediate actions
- Deploy 802.1X network access control on physical switch ports, disable unused ports, and enforce MAC limiting to block rogue hardware implants
- Block execution from user-writable directories and mount /tmp and /home with noexec
- Segment networks to block SMB (445) and RDP (3389) between workstation and server VLANs
- Alert on and restrict unauthorized/portable RMM tool execution (e.g. AnyDesk) and block unapproved system service/daemon registrations
Workarounds
- Restrict administrative utilities such as ntdsutil.exe and vssadmin.exe to authorized admin workstations
- Block egress to non-essential ports/protocols and to public paste sites such as dontpad.com; apply SSL/TLS decryption and DPI to outbound traffic
Longer-term hardening
- Enforce PowerShell Constrained Language Mode and enable Script Block Logging (Event ID 4104)
- Move mTLS certificates and administrative credentials into a centralized secrets manager (e.g. HashiCorp Vault) behind dedicated PAM jump hosts
- Mandate phishing-resistant MFA on all external portals, RMM tools, and VPN access points
- Apply Kubernetes RBAC least privilege, Pod Security Admission, and dynamic admission controllers (OPA Gatekeeper/Kyverno) to prevent CI/CD and cloud secret exfiltration
Timeline of BREEZE COMET (ex-UNC5669) Targets Brazilian Financial
- CrowdStrike first tracks a Brazil-based eCrime adversary, PLUMP SPIDER (community ID SHADOW-AETHER-064), later attributed by Mandiant as UNC5669 / BREEZE COMET.
- Actor conducts opportunistic Brazilian retail banking fraud via password spraying and vishing calls that trick staff into installing the AnyDesk RMM tool for initial access.
- Actor begins inserting rogue physical hardware implants directly into retail store networks to establish footholds for lateral movement.
- The compromised-government-website staging technique is replicated on government domains in Nigeria (mrtb.gov.ng), Guinea (credeb.gov.gn), Paraguay (jmcov.gov.py), and Venezuela (sit.baer.gob.ve).
- Actor begins staging payloads and command-and-control infrastructure on compromised Brazilian municipal government websites to bypass network domain-reputation filtering.
- Axur reports BREEZE COMET/Plump Spider expanding beyond banking institutions to insurance companies, retail businesses, and point-of-sale system providers.
- Axur publishes updated modus-operandi reporting detailing insider-recruitment offers to managers, IT staff, and VPN-privileged employees, including an 80-minute vishing call in which operators posed as IT support and requested screenshots to build credibility.
- Mandiant identifies direct evidence that large language models accelerated the actor's development of reconnaissance, credential-validation, mass-deployment, and data-extraction scripts.
- Actor shifts from commercial RMM tools to a custom, redundant multi-language backdoor suite (COBALTSPIN, REALBREEZE, LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM) alongside XWORM, enabling direct intrusions into core financial-switch infrastructure.
- Google Threat Intelligence Group and Mandiant publish the public BREEZE COMET threat actor profile, renaming UNC5669/Plump Spider.
- Actor achieves access to core financial-switch/instant-payment infrastructure and executes two waves of hundreds of fraudulent transactions within 24-48 hours, netting tens of thousands of USD in at least one confirmed heist.
Update history for TL-2026-2266
- 2026-09-02 — BREEZE COMET (formerly UNC5669 / Plump Spider) Uses AI-Assisted Custom Malware to Defraud Brazilian Banks via Pix, STR, and Boleto: What changed Severity HIGH → CRITICAL: new reporting (Axur, Trend Micro) reveals an HSM/pacs.008 payment-order-signing abuse technique where the legitimate application itself signs a fraudulent payment order (no private-key exfiltration nee
Sources cited for BREEZE COMET (ex-UNC5669) Targets Brazilian Financial
More in apt
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and DCSync to Compromise Russian Active Directory
- North Korean WaterPlum (Contagious Interview) Campaign Infects 30,000 Devices, Steals $10.71M in Crypto via Fake Job Interviews and npm/PyPI/Go/Rust Supply-Chain Packages
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle Malware
- SilkParasite Infrastructure Links SpiceRAT, NodeEdgeRAT, and NomadRAT to Four-Year China-Nexus Campaign Against Central Asian Governments
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and Afghanistan Government/Defense Targets
Detection coverage for TL-2026-2266
As of 2026-09-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2266 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2266
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.