<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm" -->

---
title: Financially Motivated Threat Actor BREEZE COMET Targets...
description: Mandiant and Google Threat Intelligence Group detail BREEZE COMET (formerly UNC5669), a financially motivated threat actor targeting Brazilian financial...
canonical: https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Financially Motivated Threat Actor BREEZE COMET Targets Brazil | daily.dev
og:description: Mandiant and Google Threat Intelligence Group detail BREEZE COMET (formerly UNC5669), a financially motivated threat actor targeting Brazilian financial...
og:url: https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm
og:image: https://api.daily.dev/og/posts/MI7uWDXTm.png
og:image:alt: Financially Motivated Threat Actor BREEZE COMET Targets Brazil
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Financially Motivated Threat Actor BREEZE COMET Targets Brazil

**[Google Cloud](https://daily.dev/sources/gcp)** · 12 min read · 0 upvotes · 0 comments

## Summary

Mandiant and Google Threat Intelligence Group detail BREEZE COMET (formerly UNC5669), a financially motivated threat actor targeting Brazilian financial services, retail, and eCommerce organizations since 2024 to conduct fraudulent Pix, STR, and Boleto transfers. The group uses password spraying, voice phishing, compromised government websites, rogue hardware devices in retail networks, and JBoss AS exploitation for initial access. Custom malware includes REALBREEZE (LDAP brute-forcer), COBALTSPIN (Rust-based network tunneler), and backdoors LIGHTPAINT (Java), MILDFROST (Java JAR with DNS tunneling), KICKPLATE (Nim), and BOATBEAM (Golang). The group also uses LLMs to accelerate script development for reconnaissance and deployment, and has expanded infrastructure to Nigeria, Paraguay, Ghana, and Venezuela. Extensive mitigation recommendations, IOCs, and YARA rules are provided.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil>

## Questions this post answers

### What malware tools does the BREEZE COMET threat actor use to target Brazilian financial systems?

BREEZE COMET uses a custom malware suite including REALBREEZE, an LDAP brute-forcing utility; COBALTSPIN, a Rust-based network tunneler using reverse SOCKS5 over WebSocket; and four backdoors for redundant persistence: LIGHTPAINT (Java, installs SoftEther VPN), MILDFROST (Java JAR with DNS tunneling), KICKPLATE (Nim, impersonates Windows Update Health Tools), and BOATBEAM (Golang, fakes an IIS HTTPS server on port 443).

_Security teams tracking emerging financial malware families can follow threat research like this on daily.dev._

### How are attackers using generative AI in financially motivated cyberattacks against banks?

BREEZE COMET, a threat actor targeting Brazilian financial services, uses large language models to accelerate creation of custom scripts for network reconnaissance, credential validation, mass deployment, and data extraction. Analysts noted the AI-generated scripts lack human idiosyncrasies, relying on unrolled code structures, verbose explanatory comments, and standardized execution headers, which compresses development time and lowers the technical barrier for coordinated multi-environment attacks.

_Developers and defenders evaluating how AI reshapes attacker tradecraft can track this coverage on daily.dev._

### How did BREEZE COMET gain initial access to Brazilian financial and retail networks?

BREEZE COMET used password spraying, voice phishing impersonating IT support to install RMM tools like AnyDesk, compromised small Brazilian government websites to stage infostealers and XWORM backdoors, rogue hardware devices plugged directly into retail store networks, and exploitation of vulnerabilities in JBoss AS servers, with the group later expanding similar infrastructure to Nigeria, Paraguay, Ghana, and Venezuela.

_Incident responders defending financial infrastructure can keep up with attacker access techniques via daily.dev._

## Similar posts on daily.dev

- ['Several dozen' orgs targeted by a new extortion crew](https://daily.dev/posts/several-dozen-orgs-targeted-by-a-new-extortion-crew-hwkvov6ma) · The Register · 0 upvotes · 0 comments
- [Ongoing Targeted Campaign Against US Law Firms](https://daily.dev/posts/ongoing-targeted-campaign-against-us-law-firms-r3ufz8uzn) · Google Cloud · 0 upvotes · 0 comments

---

Tags: [#kubernetes](https://daily.dev/tags/kubernetes), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Financially Motivated Threat Actor BREEZE COMET Targets Brazil","url":"https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm"},"datePublished":"2026-09-01T03:06:08.798Z","dateModified":"2026-09-01T03:23:56.589Z","description":"Mandiant and Google Threat Intelligence Group detail BREEZE COMET (formerly UNC5669), a financially motivated threat actor targeting Brazilian financial...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/efb6ebdd31507ed6cdc6e0fe53ac3537?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/efb6ebdd31507ed6cdc6e0fe53ac3537?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Google Cloud","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Google Cloud","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/gcp","url":"https://daily.dev/sources/gcp"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"kubernetes,malware","timeRequired":"PT12M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Google Cloud","item":"https://daily.dev/sources/gcp"},{"@type":"ListItem","position":3,"name":"Financially Motivated Threat Actor BREEZE COMET Targets Brazil"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/financially-motivated-threat-actor-breeze-comet-targets-brazil-mi7uwdxtm#faq","mainEntity":[{"@type":"Question","name":"What malware tools does the BREEZE COMET threat actor use to target Brazilian financial systems?","acceptedAnswer":{"@type":"Answer","text":"BREEZE COMET uses a custom malware suite including REALBREEZE, an LDAP brute-forcing utility; COBALTSPIN, a Rust-based network tunneler using reverse SOCKS5 over WebSocket; and four backdoors for redundant persistence: LIGHTPAINT (Java, installs SoftEther VPN), MILDFROST (Java JAR with DNS tunneling), KICKPLATE (Nim, impersonates Windows Update Health Tools), and BOATBEAM (Golang, fakes an IIS HTTPS server on port 443). Security teams tracking emerging financial malware families can follow threat research like this on daily.dev."}},{"@type":"Question","name":"How are attackers using generative AI in financially motivated cyberattacks against banks?","acceptedAnswer":{"@type":"Answer","text":"BREEZE COMET, a threat actor targeting Brazilian financial services, uses large language models to accelerate creation of custom scripts for network reconnaissance, credential validation, mass deployment, and data extraction. Analysts noted the AI-generated scripts lack human idiosyncrasies, relying on unrolled code structures, verbose explanatory comments, and standardized execution headers, which compresses development time and lowers the technical barrier for coordinated multi-environment attacks. Developers and defenders evaluating how AI reshapes attacker tradecraft can track this coverage on daily.dev."}},{"@type":"Question","name":"How did BREEZE COMET gain initial access to Brazilian financial and retail networks?","acceptedAnswer":{"@type":"Answer","text":"BREEZE COMET used password spraying, voice phishing impersonating IT support to install RMM tools like AnyDesk, compromised small Brazilian government websites to stage infostealers and XWORM backdoors, rogue hardware devices plugged directly into retail store networks, and exploitation of vulnerabilities in JBoss AS servers, with the group later expanding similar infrastructure to Nigeria, Paraguay, Ghana, and Venezuela. Incident responders defending financial infrastructure can keep up with attacker access techniques via daily.dev."}}]}
```

