MILDFROST is a passive Java backdoor used by the financially motivated threat actor BREEZE COMET (formerly UNC5669). It provides redundant persistent access in intrusions targeting Brazilian financial-services, payment, retail, and e-commerce organizations. The backdoor supports command execution and file transfer functionality, and can establish covert DNS tunnels as a fallback command-and-control channel. BREEZE COMET deploys MILDFROST alongside other custom backdoors while pursuing access to banking software, payment APIs, privileged accounts, and payment-transfer infrastructure for fraudulent transactions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Persistence is achieved through custom backdoors like LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom backdoor used by Breeze Comet to maintain persistence after compromising targets connected to Brazilian payment and banking systems.
A backdoor capable of using DNS tunneling as a low-noise fallback command-and-control channel; associated artifacts include the Java class DnsCommandBeacon.class.
Passive Java JAR backdoor used to establish covert DNS tunnels.
Passive Java backdoor using covert DNS tunnels, including DnsCommandBeacon.class, as fallback command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.