BREEZE COMET, formerly tracked as UNC5669, is a financially motivated cybercriminal threat actor active since 2024 and assessed to operate from Brazil. Its activity overlaps with clusters publicly tracked as Plump Spider and SHADOW-AETHER-064. The group targets Brazilian banks, payment processors, fintechs, cryptocurrency exchanges, retailers, e-commerce organizations, and banking-software providers that can submit transactions through banking software, financial APIs, and payment systems including Pix, STR, and Boleto. Its objective is fraudulent transfer activity using compromised privileged accounts, payment-system access, and transaction-authentication material. BREEZE COMET gains initial access through password spraying, voice phishing that impersonates IT support personnel, exploitation of vulnerable JBoss AS servers, deployment of unauthorized hardware on retail networks, and malicious content hosted on compromised public-sector websites. It performs internal reconnaissance, scans internal networks, abuses service accounts, and moves laterally over RDP and SMB. The actor seeks Active Directory, cloud, CI/CD, API, certificate, and mTLS credentials, then uses tunneling and proxy tooling to reach core financial applications across network boundaries. The group uses custom backdoors including LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM, REALBREEZE, and COBALTSPIN, as well as commodity remote-management and post-exploitation tools. It establishes persistence through backdoors, service and startup modifications, and malicious Kubernetes workloads; it also uses DNS tunneling and reverse proxying. BREEZE COMET has disabled endpoint protections, cleared event logs, and deleted artifacts after conducting large volumes of fraudulent transactions. Evidence also indicates use of generative AI to accelerate development of reconnaissance, credential-validation, deployment, routing, and data-extraction scripts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated actor conducting payment-system and banking-software fraud in Brazil. It obtains access through password spraying, IT-support impersonation and vulnerable JBoss AS servers, then performs reconnaissance, lateral movement, persistence, and fraudulent fund transfers.
A financially motivated payment-fraud group targeting banking, payment, retail, and eCommerce environments. It obtains trusted access to financial systems and submits fraudulent transfers through legitimate channels, including Pix, STR, and Boleto. The group has operated since 2024 and has targeted organizations in Brazil, with infrastructure patterns potentially indicating a broader Latin American and African footprint.
Brazil-based financially motivated e-crime group conducting direct intrusions into financial institutions, payment processors, retailers, exchanges, and fintech providers to manipulate banking software, payment APIs, and payment systems for fraudulent transfers. The group uses social engineering, password spraying, RMM abuse, web shells, custom malware, proxy tunneling, cloud-secret theft, lateral movement, and log clearing to access and fraudulently transact through Pix, STR, Boleto, and core financial infrastructure.
Financially motivated operations against Brazil's financial and retail sectors, manipulating banking software, APIs, and payment systems to conduct fraudulent transfers. The group uses custom malware, compromised trusted websites, persistent access, and C2 infrastructure to support reconnaissance, lateral movement, persistence, and exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.