Threat Advisory

BREEZE COMET Uses COBALTSPIN to Compromise Financial Software and Payment Systems

Threat: Malware
Threat Actor Name: BREEZE COMET
Threat Actor Type: Financially Motivated
Targeted Region: Latin America, Brazil
Threat Actor Region: Brazil
Targeted Sector: Finance & Banking, Retail & E-commerce
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

BREEZE COMET is a financially motivated threat actor that compromises privileged accounts to access core financial applications, executing hundreds of fraudulent transactions within 24-48 hours. The attacker uses bespoke reconnaissance scripts generated by LLMs to automate deployment workflows and validate credentials on the fly. Forensic evidence analyzed by Mandiant demonstrates that BREEZE COMET used COBALTSPIN and compromised privileged accounts to access core financial applications. Within 24-48 hours of establishing this access, the threat actor executed two waves of hundreds of fraudulent transactions.

The attacker also leveraged LLMs to generate bespoke reconnaissance scripts, validate credentials, and automate deployment workflows on the fly. This automation compressed the development lifecycle and lowered the operational threshold required to coordinate synchronized, multi-environment attacks. BREEZE COMET has steadily increased the complexity and effectiveness of their operations manipulating Brazilian financial systems and software since.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

BREEZE COMET is a financially motivated threat actor that compromises privileged accounts to access core financial applications, executing hundreds of fraudulent transactions within 24-48 hours. The attacker uses bespoke reconnaissance scripts generated by LLMs to automate deployment workflows and validate credentials on the fly. Forensic evidence analyzed by Mandiant demonstrates that BREEZE COMET used COBALTSPIN and compromised privileged accounts to access core financial applications. Within 24-48 hours of establishing this access, the threat actor executed two waves of hundreds of fraudulent transactions.

The attacker also leveraged LLMs to generate bespoke reconnaissance scripts, validate credentials, and automate deployment workflows on the fly. This automation compressed the development lifecycle and lowered the operational threshold required to coordinate synchronized, multi-environment attacks. BREEZE COMET has steadily increased the complexity and effectiveness of their operations manipulating Brazilian financial systems and software since.[emaillocker id="1283"]

The threat actor's campaigns represent a notable shift in targeting core financial switch and instant payment infrastructure, demonstrating capabilities that may serve as a model for future financially motivated threats against organizations in Latin America. This transition highlights the maturation of BREEZE COMET's technical capability and the need for defenders to anticipate shorter adversary turnaround times and heightened pressure on interconnected financial ecosystems.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Discovery T1082 System Information Discovery -
Collection T1005 Data from Local System -
Exfiltration T1041 Exfiltration Over C2 Channel -

MBC MAPPING:

Objective Behavior ID Behavior
Execution E1204 User Execution
Command & Control B0030 C2 Communication
Anti-Static Analysis E1027 Obfuscated Files or Information
Discovery E1082 System Information Discovery
Exfiltration E1020 Automated Exfiltration
Persistence F0012 Registry Run Keys / Startup Folder

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu