THE report details the activities of BREEZE COMET, a financially motivated threat actor targeting Brazilian financial and retail sectors since 2024. This group manipulates payment and banking systems for fraudulent transactions, leveraging custom malware, compromised websites, and AI tools for operational efficiency. Key tactics include initial access via password spraying, RMM tool deployment, and lateral movements using specialized malware.
BREEZE COMET has escalated privileges in target environments, focusing on the National Financial System and cloud-driven resources. The threat actor has executed mass fraudulent transactions, demonstrating sophisticated techniques in financial cybercrime. The report outlines remediation strategies for organizations, emphasizing network access control, endpoint defense, and application security measures to mitigate risks from such advanced threats.