A financially motivated actor has moved beyond stealing consumer banking logins and into the systems that authorize payments. In its BREEZE COMET report, Google Threat Intelligence Group and Mandiant connect privileged access to core financial applications with two waves of hundreds of fraudulent transactions, executed within 24 to 48 hours.
The group’s target is unusually specific. “BREEZE COMET operations target organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto,” GTIG wrote. Banks, payment processors, retailers, exchanges, fintechs and banking-software providers all sit inside that scope.
The campaign began appearing in Mandiant investigations in 2024. GTIG tracks it as BREEZE COMET, formerly UNC5669, with overlap to activity called Plump Spider and SHADOW-AETHER-064 by other researchers. GTIG is a security vendor reporting its own incident-response and telemetry findings. The public report does not quantify the number of victims, the total loss, or how widely each custom backdoor was deployed.
Trusted sites deliver footholds
BREEZE COMET has used several entry paths rather than a single exploit chain. Mandiant observed password spraying and phone calls from people impersonating IT support. The callers persuaded users to install remote-management software such as AnyDesk. Other operations used infostealers disguised as tax or receipt documents, XWORM, vulnerable JBoss servers and compromised municipal websites.
Those government sites mattered because their reputation helped the traffic pass domain-based filters. GTIG found the same staging infrastructure serving payloads across operations and saw similar municipal-domain abuse in Nigeria, Paraguay, Ghana and Venezuela. These were legitimate shared services that attackers compromised. Their hostnames are hunting context. A visit alone does not show that the visitor or the public body was malicious.
The most physical intrusion was a rogue device connected directly to a retail store network. From that foothold, the actor moved to internal systems, downloaded Netcat and custom scripts, and pulled later tooling from external directories. An organization that watches only email and internet-facing servers could miss that branch-network path entirely.

Long description
The diagram begins with three initial-access lanes: IT-support voice phishing and RMM installation, compromised trusted websites serving payloads, and rogue hardware attached inside a retail network. The lanes converge on credential discovery across Active Directory, cloud, CI/CD and host files. A second stage shows stolen mTLS credentials and privileged accounts opening access to financial applications. COBALTSPIN carries traffic through segmented networks, while four backdoors preserve redundant access. The final stage shows two waves of hundreds of fraudulent transactions within 24 to 48 hours. A side note marks the limits of the evidence: Mandiant did not publish a victim count or total loss.
Stolen credentials reach payment rails
Once inside, BREEZE COMET enumerates Active Directory and searches development and cloud environments. GTIG observed the actor mining CI/CD systems for hard-coded pipeline credentials, API keys and privileged cloud tokens. Custom scripts also searched host files and environment variables for mTLS credentials and administrative certificates used by core banking systems.
The search strings reveal the business objective: boleto | cnab | remessa | webhook.*pix | instant.*payment. Those terms point toward Brazilian payment files, remittance workflows, Pix webhooks and instant-payment integrations. The actor also hijacked service accounts for RDP and used SMB shares for command execution and movement across internal subnets.
COBALTSPIN then supplied a reverse SOCKS5 proxy over WebSocket. That tunnel let operators route traffic through boundary firewalls toward financial API infrastructure. Mandiant’s evidence shows the group using COBALTSPIN and compromised privileged accounts to reach core financial applications before the transaction waves began.
GTIG says the actor used generative AI to accelerate reconnaissance, credential validation, mass deployment, victim-specific pivoting and extraction scripts. Recovered tools were functional and highly customized, with verbose comments and standardized headers. The evidence supports faster tool development. It does not establish a fully autonomous intrusion.
Five tools preserve access
BREEZE COMET built redundancy around the payment path. REALBREEZE brute-forced LDAP credentials. LIGHTPAINT installed a legitimate VPN such as SoftEther, added inbound firewall rules and cleared the Windows Networking Vpn Plugin Platform event log. MILDFROST hid as a Java JAR in the JVM process space and used DnsCommandBeacon.class for a slow DNS tunnel.
KICKPLATE, a Nim backdoor posing as Windows Update Health Tools, managed SOCKS5 tunnelers, registry startup keys and Windows services. BOATBEAM presented a fake IIS HTTPS service on port 443 and activated its backdoor behavior after a specific session cookie. The actor also used scheduled tasks running as SYSTEM and issued Set-MpPreference -DisableRealtimeMonitoring $true to disable Microsoft Defender real-time monitoring.
That access ended in concrete fraud. A client report and third-party forensic analysis tied privileged application access to hundreds of transactions in two waves. GTIG separately says at least one heist took tens of thousands of US dollars. Those are documented outcomes, while aggregate loss and victim count remain undisclosed.
Hunt the published evidence
Start recognition with the source’s file hashes. Search endpoint telemetry, malware repositories, EDR records and retained forensic images for these values:
| Family | SHA-256 |
|---|---|
| COBALTSPIN | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec |
| REALBREEZE | 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a |
| MILDFROST | c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a |
| BOATBEAM | 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb |
| KICKPLATE | f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f |
| XWORM | 51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6 |
| XWORM | d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66 |
| XWORM | 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8 |
Review proxy, DNS and download logs for the following legitimate services and compromised government hostnames. Keep them in context: the actor abused dontpad.com, procon.go.gov.br, cmgovernadorluizrocha.ma.gov.br, gcm.setelagoas.mg.gov.br, minacu.go.gov.br, conseg.ssp.go.gov.br, suporte.camaratunapolis.sc.gov.br, tisup.camaratunapolis.sc.gov.br, suporte.ourinhos.sp.gov.br, servicos.salto.sp.gov.br, www.mrtb.gov.ng, credeb.gov.gn, sit.baer.gob.ve and jmcov.gov.py. A hostname match needs correlation with unexpected executable or archive downloads, the published hashes, new RMM activity, suspicious service creation, or financial-system access.
Google SecOps customers can check for Network DNS Connections To Pastebin, Powershell Downloadstring Method With Suspicious Arguments and Powershell Loading Net Assembly. Other defenders can translate the same behavior into their platform: inspect PowerShell Script Block Logging event 4104, newly registered services, scheduled tasks running as SYSTEM, Defender preference changes, outbound DNS tunneling and WebSocket-based SOCKS5 traffic. Preserve logs before isolation because BREEZE COMET has cleared them.
Containment should break the route to payment authority. Block unapproved RMM tools with application control, require phishing-resistant MFA on external portals, rotate exposed pipeline, cloud and mTLS credentials, and segment SMB port 445 and RDP port 3389 between workstations and servers. Enforce 802.1X on branch switch ports so an unauthorized device cannot obtain network access. Restrict Kubernetes service accounts, privileged pods and public egress, and move plaintext keys into a logged secrets manager.
Verify the response by correlating four records across the incident window: the initial access event, credential access, the tunnel or persistence mechanism, and payment-application activity. The expected result is a documented disposition for every matching host and identity, rotated financial credentials, blocked unauthorized branch access, and no unexplained transaction or API activity after containment. A clean malware scan alone cannot establish that payment authority remained safe.
