Google Threat Intelligence Group has identified BREEZE COMET (formerly UNC5669) as a financially motivated actor targeting Brazilian financial services, retail, and e-commerce organizations to conduct fraudulent transfers. The group seeks access to Brazil's financial transaction ecosystem, including RSFN-connected entities, mutual-TLS credentials, banking and payment APIs, and persistent Active Directory or cloud environments.
BREEZE COMET gains access through voice phishing, password spraying, compromised government websites, rogue hardware on retail networks, and reportedly exploitation of JBoss AS. Its toolset includes XWORM, REALBREEZE, COBALTSPIN, BOATBEAM, and MILDFROST, supplemented by legitimate utilities for reconnaissance, credential theft, lateral movement, tunneling, and data exfiltration. GTIG reported the actor has reused compromised municipal infrastructure in Nigeria, Paraguay, Ghana, and Venezuela, indicating potential expansion across Latin America and Africa, and has evidence of its use of generative AI in malware development.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
In a November 2025 case, BREEZE COMET actors impersonated IT support personnel over WhatsApp and persuaded a victim to install a PowerShell reconnaissance script disguised as a corporate-application update.
By mid-2025, BREEZE COMET used compromised Brazilian small-government websites to host RMM tools, tax- or receipt-themed infostealers, and XWORM. The actor also used the sites as command-and-control endpoints and reused municipal-domain infrastructure across operations.
BREEZE COMET connected rogue hardware devices to retail-store networks to gain initial access, then moved laterally and retrieved post-exploitation frameworks using Netcat and custom scripts.
Mandiant began investigating a string of compromises affecting Brazilian financial-services, retail, and eCommerce organizations. The actor targeted payment systems and banking software to conduct fraudulent transfers.
Reporting disclosed that BREEZE COMET used password spraying, vulnerable JBoss AS servers, RDP/SMB, Impacket, and backdoors including LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM. The group reportedly disabled Windows Defender, used compromised accounts and COBALTSPIN to conduct fraudulent transactions, cleared logs afterward, and carried out at least one theft worth tens of thousands of U.S. dollars.
Reporting identified evidence that BREEZE COMET (UNC5669) uses generative AI to assist malware development. The report also disclosed campaign indicators, including malicious payload-hosting URLs on compromised sites, the dontpad.com domain, and eight associated SHA-256 hashes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecommunity.gurucul.com
Open sourcecloud.google.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.