cloud.google.com 9/1/2026, 3:51:09 AM · external

BREEZE COMET Fuels Bank Fraud in Brazil with AI Boosted Malware

BREEZE COMET Fuels Bank Fraud in Brazil with AI Boosted Malware
Developing story malware 2 articles tracked
BREEZE COMET conducts Pix fraud campaign against Brazilian banks
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
BREEZE COMET

THE report details the activities of BREEZE COMET, a financially motivated threat actor targeting Brazilian financial and retail sectors since 2024. This group manipulates payment and banking systems for fraudulent transactions, leveraging custom malware, compromised websites, and AI tools for operational efficiency. Key tactics include initial access via password spraying, RMM tool deployment, and lateral movements using specialized malware.

BREEZE COMET has escalated privileges in target environments, focusing on the National Financial System and cloud-driven resources. The threat actor has executed mass fraudulent transactions, demonstrating sophisticated techniques in financial cybercrime. The report outlines remediation strategies for organizations, emphasizing network access control, endpoint defense, and application security measures to mitigate risks from such advanced threats.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline