Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Financially Motivated Threat Actor Targets Brazil

0
Medium
Published: 09/01/2026 (09/01/2026, 07:05:40 UTC)
Source: AlienVault OTX General

Description

Beginning in 2024, a financially motivated threat actor designated BREEZE COMET has conducted sophisticated operations targeting Brazilian financial services, retail, and eCommerce organizations. The group specializes in manipulating payment systems including Pix, STR, and Boleto to conduct fraudulent transfers worth tens of thousands of USD. Their evolved tactics leverage customized malware suites written in multiple languages including Rust, Nim, Golang, and Java, alongside compromised government websites for initial access and command and control. The threat actor demonstrates advanced capabilities by targeting banking software, payment APIs, and mTLS credentials while maintaining persistent access through multiple backdoors. Evidence indicates BREEZE COMET uses generative AI to accelerate malware development and script creation, suggesting potential expansion to other Latin American and African countries based on infrastructure replication observed in Nigeria, Paraguay, Ghana, and Venezuela.

Technical Details

Author
AlienVault
Tlp
white
References
["https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/"]
Adversary
BREEZE COMET
Pulse Id
6a9679441f068d4ee93916ae
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainminacu.go.gov.br
domainservicos.salto.sp.gov.br
domainjmcov.gov.py
domainsit.baer.gob.ve
domainsuporte.camaratunapolis.sc.gov.br
domaintisup.camaratunapolis.sc.gov.br
domainwww.mrtb.gov.ng
domainattvpn.vip
domaincmgovernadorluizrocha.ma.gov.br
domainprocon.go.gov.br
domainconseg.ssp.go.gov.br
domaingcm.setelagoas.mg.gov.br
domainsuporte.ourinhos.sp.gov.br

Url

ValueDescriptionCopy
urlhttps://sit.baer.gob.ve/r.exe
urlhttps://minacu.go.gov.br/ComprovantePDF.exe
urlhttp://credeb.gov.gn/r.zip
urlhttp://gcm.setelagoas.mg.gov.br/files/notepadd.exe
urlhttp://gcm.setelagoas.mg.gov.br/files/tes.exe
urlhttp://gcm.setelagoas.mg.gov.br/files/ti.zip
urlhttp://suporte.ourinhos.sp.gov.br/files/a.exe
urlhttp://suporte.ourinhos.sp.gov.br/files/s.zip
urlhttp://suporte.ourinhos.sp.gov.br:443/files/s.exe
urlhttps://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe
urlhttps://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe
urlhttps://conseg.ssp.go.gov.br/ComprovanteBBpix.exe
urlhttps://jmcov.gov.py/cxv.exe
urlhttps://procon.go.gov.br/ComprovantePDF.exe
urlhttps://servicos.salto.sp.gov.br/j.jar
urlhttps://suporte.camaratunapolis.sc.gov.br/ti/1.exe
urlhttps://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip
urlhttps://tisup.camaratunapolis.sc.gov.br/SoftEther.exe
urlhttps://www.mrtb.gov.ng/apps/attvpn.vip

Hash

ValueDescriptionCopy
hash599f80a79efdc584c70f4f763c663b06d432393c
hash51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6
hash833368e3029a38a4f87207acd537070e
hashd2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66
hash3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec
hashf0cfe3559bf988d4477a6ac2bcc6c025
hash31f578c8d2d51bc91b7dfe4d663cb0ad079d5869
hash6652cf491ed9992eb2f3af23e9641cd987096280
hash0ef9f39b2685b42c78fc6859498b29bf
hashf139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f
hash54e3e03c168899fe9e3ecea2c46b5359
hashcd382e301231bb1a86ad06e9d492dbfce6a43fab
hash2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a
hash447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8
hashf25b2229715bd66e783ecde70843f01d
hashc23d24b2888d02998f7c0f6091ab2e69fbac4a3e
hash6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb
hashc0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a
hash08cbd834a5bb5f402d771003f437c206a0a67c6e
hash419df93671ff0eedc118a641bab30584f84d16a6
hash9bd6d2a99a5a63805578d775fdedc7dc2ad765fa
hashea259f3e37f87ddb3d619a7fecb072471af97c3a

Threat ID: 6a968ebbacd9273b4971298b

Added to database: 09/01/2026, 08:37:15 UTC

Last updated: 09/01/2026, 12:52:49 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses