Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud
BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud
Read Time:3 Minute, 53 Second

A financially motivated hacking group tracked as BREEZE COMET — previously known as UNC5669 — has spent roughly two years working its way into Brazilian banks, payment processors, and retailers with a single goal: gaining trusted access to the rails that move money, then pushing fraudulent transfers straight through legitimate channels. New research from Google Cloud’s threat intelligence team, shared with cybersecurity outlets, details a campaign that blends old-fashioned social engineering with AI-assisted tooling to compress the time between initial compromise and cashing out.

Getting In: Phone Calls, Poisoned Portals, and Rogue Hardware

BREEZE COMET’s intrusion techniques read like a greatest-hits list of enterprise attack vectors rather than a single clever trick. Early campaigns relied on password spraying and voice-phishing calls in which operators impersonated IT support staff and talked victims into installing remote management software. Later waves shifted toward compromising public-facing municipal and government websites, using them to host lures disguised as tax receipts or official documents that quietly delivered malware instead.

In some cases, the group went physical: connecting rogue devices directly to retail store networks and using that foothold to move laterally into corporate systems. The pattern echoes a growing trend security researchers have flagged around hijacked finance mailboxes and trusted-access abuse, where legitimate internal relationships and workflows become the attacker’s cover rather than a barrier.

AI as a Force Multiplier, Not a Replacement

What distinguishes BREEZE COMET from a typical financial-fraud crew is its use of generative AI to accelerate the unglamorous parts of an intrusion. Once inside a network, the group appears to lean on large language models to help write scripts for network discovery, credential validation against harvested password lists, mass deployment of its tools across compromised hosts, and routing logic tailored to each individual victim environment.

Google Cloud researchers were careful to note that AI didn’t replace the group’s criminal expertise — it shortened the time needed to adapt existing tools to a new target. In practice, that means defenders may have measurably less time between a suspicious first login and an attempted fraudulent payment, especially in cases where several compromised environments are being managed by the same operator simultaneously.

A Custom Toolkit Built for Persistence and Concealment

BREEZE COMET’s malware arsenal is built around maintaining quiet, redundant access. A tool called REALBREEZE attempts to guess directory credentials, while COBALTSPIN, written in Rust, tunnels traffic through a reverse SOCKS5 proxy layered over WebSocket connections to blend in with legitimate web traffic. A rotating cast of backdoors — LIGHTPAINT, MILDFROST, KICKPLATE, and BOATBEAM — provide overlapping access paths: LIGHTPAINT installs a VPN client, MILDFROST can fall back to DNS-based command and control for a quieter channel, KICKPLATE manipulates startup settings and system services, and BOATBEAM disguises its traffic behind a fake HTTPS server.

The group also actively hunts for developer and cloud secrets — pipeline credentials, API keys, cloud tokens, and mTLS certificates — since those materials can widen a single compromised account into control over an organization’s broader financial infrastructure, including systems tied to Brazil’s Pix instant-payment network, STR wire transfers, and Boleto payment slips.

From Access to Cash-Out in Under 48 Hours

Google Cloud documented at least one case where BREEZE COMET used COBALTSPIN and a set of compromised privileged accounts to reach core financial applications, then executed two separate waves containing hundreds of fraudulent transactions within a 24-to-48-hour window. Afterward, the group cleared logs and deleted directories in an attempt to erase evidence of the intrusion — a compressed timeline that leaves little room for a slow incident-response process.

Defensive Priorities for Financial and Retail Networks

Researchers recommend a layered response that treats both the digital and physical attack surface as equally important:

  • Block unapproved remote management tools and prevent executables from running out of user-writable folders
  • Give employees a clear, verified channel to confirm unexpected “IT support” calls before granting remote access
  • Enforce phishing-resistant MFA and account lockout policies on external-facing portals
  • Deploy 802.1X network access control in retail and branch locations, disable unused switch ports, and physically secure network closets to prevent rogue devices from joining internal networks
  • Apply least-privilege policies to Kubernetes service accounts, block privileged containers, and keep secrets out of source code and environment files
  • Monitor for unusual PowerShell activity, new services, DNS tunneling patterns, and unexpected access to payment APIs

Google Cloud also warned that BREEZE COMET’s infrastructure patterns suggest the group’s reach may extend beyond Brazil into other parts of Latin America and Africa, making this less a regional curiosity and more an early look at how AI-assisted tooling is reshaping financially motivated intrusions against payment infrastructure globally.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud, use the discussion on Forum.

>> forum community

Comments

Leave a Reply