{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/actors/breeze-comet/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["BREEZE COMET"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JBoss AS"],"_cs_severities":["high"],"_cs_tags":["financial-fraud","malware","persistence","exfiltration"],"_cs_type":"threat","_cs_vendors":["JBoss"],"content_html":"\u003cp\u003eBREEZE COMET (formerly UNC5669) is a financially motivated threat actor specializing in manipulating Brazilian financial and payment systems, including Pix, STR, and Boleto. Since 2024, the group has targeted banks, retailers, and fintech providers to conduct fraudulent transfers. Their operations are characterized by a sophisticated, custom malware suite including REALBREEZE for LDAP brute-forcing, COBALTSPIN for evasive SOCKS5 proxy tunneling, and LIGHTPAINT for VPN-based persistence.\u003c/p\u003e\n\u003cp\u003eThe actor demonstrates high operational maturity, utilizing social engineering, password spraying, and exploitation of JBoss AS servers for initial access. They specifically target CI/CD pipelines and cloud environments to harvest API keys and administrative mTLS credentials. Google Threat Intelligence Group has observed the group leveraging generative AI for malware development and expanding their infrastructure to municipal domains in Africa and Latin America, suggesting an intent to scale operations beyond Brazil.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is gained via password spraying, voice phishing (impersonation of IT), or exploitation of JBoss AS vulnerabilities.\u003c/li\u003e\n\u003cli\u003eRMM tools or infostealers (e.g., XWORM) are staged on compromised government websites and executed on victim endpoints.\u003c/li\u003e\n\u003cli\u003eAttackers perform internal reconnaissance using tools like ADRecon and custom LDAP brute-forcing utilities (REALBREEZE) to identify privileged accounts.\u003c/li\u003e\n\u003cli\u003eCI/CD pipelines are mined for hard-coded credentials, API keys, and cloud access tokens to escalate privileges within cloud environments.\u003c/li\u003e\n\u003cli\u003eLateral movement is performed via hijacked service accounts using RDP and SMB, often utilizing custom Rust-based routing malware (COBALTSPIN) for SOCKS5 tunneling.\u003c/li\u003e\n\u003cli\u003ePersistence is maintained using LIGHTPAINT, which installs a legitimate VPN (SoftEther), modifies Windows Defender Firewall rules, and clears specific event logs to hide the connection.\u003c/li\u003e\n\u003cli\u003eSearch scripts query host files and environment variables for financial keywords (e.g., 'boleto', 'pix', 'remessa') to locate mTLS credentials.\u003c/li\u003e\n\u003cli\u003eStolen credentials are used to authenticate against financial API infrastructure to initiate fraudulent transfers.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eBREEZE COMET’s activity results in significant financial loss through fraudulent transfers executed via compromised payment systems. The group targets critical financial infrastructure and retail networks, affecting financial services, retail, and eCommerce sectors. If successful, the actor achieves sustained, persistent access to internal financial networks, allowing for long-term credential theft and repeated unauthorized transactions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit and restrict access to CI/CD environments; move secrets from hard-coded variables to secure vaulting solutions.\u003c/li\u003e\n\u003cli\u003eImplement strict mTLS validation and monitor for anomalous outbound traffic from financial API integration nodes.\u003c/li\u003e\n\u003cli\u003eDeploy detection for unauthorized VPN-based connections by monitoring Windows Defender Firewall rule modifications and VPN plugin service activity.\u003c/li\u003e\n\u003cli\u003eMonitor for the execution of reconnaissance utilities like ADRecon and LDAP-querying scripts in high-privilege environments.\u003c/li\u003e\n\u003cli\u003eProactively hunt for indicators of COBALTSPIN tunnels by analyzing network traffic for long-lived, outbound WebSocket connections to unauthorized endpoints.\u003c/li\u003e\n\u003cli\u003eConfigure logging for the 'Windows Networking Vpn Plugin Platform' and alert on instances where these logs are cleared.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T05:56:33Z","date_published":"2026-09-01T05:56:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-breeze-comet/","summary":"The financially motivated actor BREEZE COMET exploits payment systems and banking software in Brazil using a custom malware suite, including LDAP brute-forcing tools and specialized network tunneling, to facilitate fraudulent transfers.","title":"BREEZE COMET Targets Brazilian Financial Systems","url":"https://feed.craftedsignal.io/briefs/2026-09-breeze-comet/"}],"language":"en","title":"CraftedSignal Threat Feed - BREEZE COMET","version":"https://jsonfeed.org/version/1.1"}