thehackernews.com 8 Sept 2026, 16:20 UTC

Slim Spider Targets Brazil’s Crypto Assets Through Cloud Attacks

CyberSIXT Evidence Panel
Threat Actor
Slim Spider

CROWDSTRIKE has linked a newly identified threat actor, named Slim Spider, to multi-stage intrusions against Brazilian financial institutions from at least March 2026. The group specialises in targeting crypto custody and instant payment assets, with evidence of cloud-credential theft and credential exfiltration from cloud credential managers.

In the observed operation, Slim Spider deployed Bash scripts that query instance metadata to harvest temporary cloud credentials, then enumerated secrets stored in cloud credential stores and used the sed command to clone and alter secret-extraction scripts focused on digital asset credentials.

After exfiltrating custody secrets, the attackers invoked cast, a Foundry Ethereum developer toolkit component, to derive the Ethereum wallet address tied to a stolen private key, while avoiding third-party libraries in favour of OpenSSL-based cloud-native signing within their Bash scripts.

According to CrowdStrike, Slim Spider moved laterally into cloud container services, deployed backdoors that mimicked legitimate infrastructure binaries, and pivoted to Azure DevOps to execute pipelines that deployed implants across a Kubernetes cluster. One implant, named spi, appeared to imitate the Brazil’s central instant payments system, SPI.

The campaign also involved web-based panels to streamline attack steps (NEXUS // Scanner for API endpoints, Painel de Emails Entra ID for mailbox reconnaissance, and Painel Pix for bulk unauthorized Pix transfers). A separate exposed command-and-control panel reportedly displayed compromised Brazil-based hosts and likely exfiltrated archives. CrowdStrike’s threat profile also links Slim Spider to MikeDor, a Go-based backdoor used to harvest data.

The activity underscores sophisticated cloud-attack surface awareness and a focus on credentials tied to digital asset custody, highlighting the risk of substantial financial losses for affected institutions.

View full article

Article by CyberSIXT