Google iconGoogleSep 1, 2026 ~1 min source read

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

In this blog, we detail BREEZE COMET's tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat. Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations.

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Share this story

Send the public story page.

Useful takeaways from this story.

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations.

This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064.

In this blog, we detail BREEZE COMET's tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In this blog, we detail BREEZE COMET's tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat.

How it works

  • BREEZE COMET tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command and control (C2), and to interact with financial...
  • BREEZE COMET's operational infrastructure may also indicate intent to expand their infrastructure footprint to other countries in Latin America and Africa.
  • Additionally, we have evidence that BREEZE COMET is using generative artificial intelligence (AI) to support malware development, which may further increase the scale, speed, and sophistication of their...
  • BREEZE COMET Targets Brazilian Financial Technology BREEZE COMET operations target organizations with permission to conduct transactions through banking software, APIs, and payment syst...

Details worth keeping

Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app