Threat Intelligence

New Cybercrime Group 'Slim Spider' Targets Brazilian Banks' Crypto and Instant Payment Systems

The Hacker News · 9 Sept 2026
Key Takeaway Financial and crypto-holding businesses should tightly restrict and monitor cloud credential access, as attackers are increasingly using native cloud tools to blend in and avoid detection.

Cybersecurity firm CrowdStrike has identified a new financially motivated hacking group, named Slim Spider, that has been targeting Brazilian financial institutions since at least March 2026. The group shows deep knowledge of Brazil's financial systems, including the Pix instant payment service, digital asset platforms, and cloud infrastructure used by financial firms.

In one documented attack, Slim Spider used custom scripts to steal temporary cloud credentials, then searched cloud secret storage for information tied to digital asset custody. The group used legitimate developer tools, including a component of the Foundry Ethereum toolkit and OpenSSL, to derive wallet addresses and perform cryptographic signing without relying on third-party libraries that might trigger security alerts. This approach reflects a strong understanding of cloud environments and a deliberate effort to avoid detection.

The attackers went on to gain access to cloud container clusters and deployed backdoors disguised as legitimate infrastructure tools. They also used compromised credentials to access Azure DevOps and run malicious pipelines, deploying further implants across a managed Kubernetes cluster, including one impersonating Brazil's official instant payment processing system.

cybercrime cryptocurrency cloud security financial services Brazil
Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.