Brazil-Focused Fraud Group 'BREEZE COMET' Targets Banks and Payment Systems, With AI Now in the Mix
Google Threat Intelligence Group has detailed a financially motivated threat actor it calls BREEZE COMET (formerly tracked as UNC5669), which has been compromising Brazilian financial services, retail and eCommerce organisations since 2024. The group specialises in manipulating banking software and payment systems, such as Pix, STR and Boleto, to carry out fraudulent transfers. This activity overlaps with operations previously reported publicly as Plump Spider and SHADOW-AETHER-064.
BREEZE COMET uses a customised malware toolkit and compromised, trusted websites to gain initial access, maintain command and control, and interact directly with financial software and payment APIs. To succeed, the group needs sustained access to national payment network credentials, persistent footholds in a target's Active Directory or cloud environment, and detailed knowledge of how an organisation processes transfers and detects fraud. Researchers also found evidence the group is using generative AI to help develop its malware, which could make future attacks faster and more sophisticated.
Google's threat intelligence team warns that BREEZE COMET's infrastructure suggests it may be looking to expand operations beyond Brazil into other parts of Latin America and Africa, making this a threat worth monitoring even outside its current target region.