<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Financial-Crime - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/financial-crime/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 16:48:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/financial-crime/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Slim Spider Targets Brazilian Financial Institutions via Cloud Infrastructure</title><link>https://feed.craftedsignal.io/briefs/2026-09-slim-spider/</link><pubDate>Tue, 08 Sep 2026 16:48:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-slim-spider/</guid><description>Slim Spider is a financially motivated actor targeting Brazilian financial organizations by stealing cloud credentials and manipulating DevOps pipelines to gain unauthorized access to digital asset custody systems and payment infrastructure.</description><content:encoded><![CDATA[<p>Slim Spider is a newly identified, Brazil-based threat actor active since at least March 2026, focusing on financial institutions and digital asset platforms. The actor demonstrates deep operational knowledge of Brazilian financial infrastructure, specifically targeting the Pix instant payment system. Their methodology involves sophisticated cloud-native attacks, moving away from traditional retail banking fraud toward direct intrusion into core financial switches. The group employs custom Bash scripts, Go-based backdoors (MikeDor), and automated tooling to enumerate cloud environments, steal temporary credentials from metadata services, and harvest secrets from credential managers. They further expand their reach by compromising Azure DevOps pipelines to deploy malicious implants - such as those impersonating the Sistema de Pagamentos Instantâneos (SPI) - into Kubernetes clusters. These actions are supported by custom reconnaissance and transaction-focused panels that categorize financial endpoints and facilitate fraudulent payments.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is established via compromised credentials to gain entry into the target organization's cloud and DevOps environment.</li>
<li>The actor performs cloud environment discovery and enumerates secrets stored within the cloud credential manager.</li>
<li>Custom Bash scripts are deployed to query cloud instance metadata and exfiltrate temporary credentials over socket connections.</li>
<li>The actor uses the 'sed' command to modify and repurpose scripts for digital asset secret extraction.</li>
<li>Attacker deploys malicious pipelines within Azure DevOps to distribute implants across managed Kubernetes clusters.</li>
<li>Backdoors mimicking infrastructure binaries are deployed to nodes to maintain persistence and blend with legitimate tooling.</li>
<li>The actor utilizes the Foundry 'cast' component to derive Ethereum wallet addresses from stolen private keys.</li>
<li>Final objective is achieved by initiating fraudulent bulk Pix payments via the compromised financial infrastructure.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Slim Spider's activities target high-value digital asset custody credentials, which can lead to catastrophic financial loss through the unauthorized transfer of cryptocurrency and fiat currency. By specifically compromising the Pix instant payment infrastructure, the actor gains the ability to execute unauthorized bulk transactions, representing a significant shift from retail banking fraud to direct financial platform exploitation within Brazil.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize monitoring of cloud and CI/CD environments for suspicious credential access and unauthorized pipeline executions.</p>
<ul>
<li>Audit and restrict access to cloud instance metadata services, particularly for containers where such access is not required.</li>
<li>Implement strict monitoring of Azure DevOps pipeline configurations for unauthorized modifications or external source integrations.</li>
<li>Monitor Kubernetes cluster logs for the deployment of unexpected container images or binaries mimicking core infrastructure components.</li>
<li>Enforce strict identity and access management controls for cloud-native secret management services to prevent bulk secret extraction.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>financial-crime</category><category>cloud-security</category><category>devops</category><category>credential-theft</category><category>kubernetes</category></item></channel></rss>