BREEZE COMET is a financially motivated threat actor that compromises privileged accounts to access core financial applications, executing hundreds of fraudulent transactions within 24-48 hours. The attacker uses bespoke reconnaissance scripts generated by LLMs to automate deployment workflows and validate credentials on the fly. Forensic evidence analyzed by Mandiant demonstrates that BREEZE COMET used COBALTSPIN and compromised privileged accounts to access core financial applications. Within 24-48 hours of establishing this access, the threat actor executed two waves of hundreds of fraudulent transactions.
The attacker also leveraged LLMs to generate bespoke reconnaissance scripts, validate credentials, and automate deployment workflows on the fly. This automation compressed the development lifecycle and lowered the operational threshold required to coordinate synchronized, multi-environment attacks. BREEZE COMET has steadily increased the complexity and effectiveness of their operations manipulating Brazilian financial systems and software since.[/subscribe_to_unlock_form]
BREEZE COMET is a financially motivated threat actor that compromises privileged accounts to access core financial applications, executing hundreds of fraudulent transactions within 24-48 hours. The attacker uses bespoke reconnaissance scripts generated by LLMs to automate deployment workflows and validate credentials on the fly. Forensic evidence analyzed by Mandiant demonstrates that BREEZE COMET used COBALTSPIN and compromised privileged accounts to access core financial applications. Within 24-48 hours of establishing this access, the threat actor executed two waves of hundreds of fraudulent transactions.
The attacker also leveraged LLMs to generate bespoke reconnaissance scripts, validate credentials, and automate deployment workflows on the fly. This automation compressed the development lifecycle and lowered the operational threshold required to coordinate synchronized, multi-environment attacks. BREEZE COMET has steadily increased the complexity and effectiveness of their operations manipulating Brazilian financial systems and software since.[emaillocker id="1283"]
The threat actor's campaigns represent a notable shift in targeting core financial switch and instant payment infrastructure, demonstrating capabilities that may serve as a model for future financially motivated threats against organizations in Latin America. This transition highlights the maturation of BREEZE COMET's technical capability and the need for defenders to anticipate shorter adversary turnaround times and heightened pressure on interconnected financial ecosystems.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Discovery | T1082 | System Information Discovery | - |
| Collection | T1005 | Data from Local System | - |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Execution | E1204 | User Execution |
| Command & Control | B0030 | C2 Communication |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
| Discovery | E1082 | System Information Discovery |
| Exfiltration | E1020 | Automated Exfiltration |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
The following reports contain further technical details:
[/emaillocker]