New Cybercrime Group 'Slim Spider' Targets Brazilian Banks' Crypto and Instant Payment Systems
Cybersecurity firm CrowdStrike has identified a new financially motivated hacking group, named Slim Spider, that has been targeting Brazilian financial institutions since at least March 2026. The group shows deep knowledge of Brazil's financial systems, including the Pix instant payment service, digital asset platforms, and cloud infrastructure used by financial firms.
In one documented attack, Slim Spider used custom scripts to steal temporary cloud credentials, then searched cloud secret storage for information tied to digital asset custody. The group used legitimate developer tools, including a component of the Foundry Ethereum toolkit and OpenSSL, to derive wallet addresses and perform cryptographic signing without relying on third-party libraries that might trigger security alerts. This approach reflects a strong understanding of cloud environments and a deliberate effort to avoid detection.
The attackers went on to gain access to cloud container clusters and deployed backdoors disguised as legitimate infrastructure tools. They also used compromised credentials to access Azure DevOps and run malicious pipelines, deploying further implants across a managed Kubernetes cluster, including one impersonating Brazil's official instant payment processing system.