{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/financial-crime/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Slim Spider"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Azure DevOps","Microsoft 365"],"_cs_severities":["high"],"_cs_tags":["financial-crime","cloud-security","devops","credential-theft","kubernetes"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eSlim Spider is a newly identified, Brazil-based threat actor active since at least March 2026, focusing on financial institutions and digital asset platforms. The actor demonstrates deep operational knowledge of Brazilian financial infrastructure, specifically targeting the Pix instant payment system. Their methodology involves sophisticated cloud-native attacks, moving away from traditional retail banking fraud toward direct intrusion into core financial switches. The group employs custom Bash scripts, Go-based backdoors (MikeDor), and automated tooling to enumerate cloud environments, steal temporary credentials from metadata services, and harvest secrets from credential managers. They further expand their reach by compromising Azure DevOps pipelines to deploy malicious implants - such as those impersonating the Sistema de Pagamentos Instantâneos (SPI) - into Kubernetes clusters. These actions are supported by custom reconnaissance and transaction-focused panels that categorize financial endpoints and facilitate fraudulent payments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial access is established via compromised credentials to gain entry into the target organization's cloud and DevOps environment.\u003c/li\u003e\n\u003cli\u003eThe actor performs cloud environment discovery and enumerates secrets stored within the cloud credential manager.\u003c/li\u003e\n\u003cli\u003eCustom Bash scripts are deployed to query cloud instance metadata and exfiltrate temporary credentials over socket connections.\u003c/li\u003e\n\u003cli\u003eThe actor uses the 'sed' command to modify and repurpose scripts for digital asset secret extraction.\u003c/li\u003e\n\u003cli\u003eAttacker deploys malicious pipelines within Azure DevOps to distribute implants across managed Kubernetes clusters.\u003c/li\u003e\n\u003cli\u003eBackdoors mimicking infrastructure binaries are deployed to nodes to maintain persistence and blend with legitimate tooling.\u003c/li\u003e\n\u003cli\u003eThe actor utilizes the Foundry 'cast' component to derive Ethereum wallet addresses from stolen private keys.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved by initiating fraudulent bulk Pix payments via the compromised financial infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSlim Spider's activities target high-value digital asset custody credentials, which can lead to catastrophic financial loss through the unauthorized transfer of cryptocurrency and fiat currency. By specifically compromising the Pix instant payment infrastructure, the actor gains the ability to execute unauthorized bulk transactions, representing a significant shift from retail banking fraud to direct financial platform exploitation within Brazil.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring of cloud and CI/CD environments for suspicious credential access and unauthorized pipeline executions.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit and restrict access to cloud instance metadata services, particularly for containers where such access is not required.\u003c/li\u003e\n\u003cli\u003eImplement strict monitoring of Azure DevOps pipeline configurations for unauthorized modifications or external source integrations.\u003c/li\u003e\n\u003cli\u003eMonitor Kubernetes cluster logs for the deployment of unexpected container images or binaries mimicking core infrastructure components.\u003c/li\u003e\n\u003cli\u003eEnforce strict identity and access management controls for cloud-native secret management services to prevent bulk secret extraction.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T16:48:26Z","date_published":"2026-09-08T16:48:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-slim-spider/","summary":"Slim Spider is a financially motivated actor targeting Brazilian financial organizations by stealing cloud credentials and manipulating DevOps pipelines to gain unauthorized access to digital asset custody systems and payment infrastructure.","title":"Slim Spider Targets Brazilian Financial Institutions via Cloud Infrastructure","url":"https://feed.craftedsignal.io/briefs/2026-09-slim-spider/"}],"language":"en","title":"CraftedSignal Threat Feed - Financial-Crime","version":"https://jsonfeed.org/version/1.1"}