Financially Motivated Threat Actor BREEZE COMET Targets Brazil

    Date: 09/01/2026

    Severity: High

    Summary

    BREEZE COMET (UNC5669) is a financially motivated threat actor targeting Brazilian banks, fintechs, retailers, exchanges, and payment providers to manipulate banking software, APIs, and payment systems such as Pix, STR, and Boleto for fraudulent transfers. The group uses custom malware, compromised trusted websites, persistent access, and C2 infrastructure for reconnaissance, lateral movement, persistence, and exfiltration, while evidence of generative AI-assisted malware development suggests its operations may become faster and more sophisticated. 

    Indicators of Compromise (IOC) List 

    Domains/URLs

    dontpad.com

    https://procon.go.gov.br/ComprovantePDF.exe

    https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe

    http://gcm.setelagoas.mg.gov.br/files/ti.zip

    http://gcm.setelagoas.mg.gov.br/files/notepadd.exe

    http://gcm.setelagoas.mg.gov.br/files/tes.exe

    https://minacu.go.gov.br/ComprovantePDF.exe

    https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe

    https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe

    https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip

    https://suporte.camaratunapolis.sc.gov.br/ti/1.exe

    https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe

    http://suporte.ourinhos.sp.gov.br/files/s.zip

    http://suporte.ourinhos.sp.gov.br:443/files/s.exe

    http://suporte.ourinhos.sp.gov.br/files/a.exe

    https://servicos.salto.sp.gov.br/j.jar

    https://www.mrtb.gov.ng/apps/attvpn.vip

    http://credeb.gov.gn/r.zip

    https://sit.baer.gob.ve/r.exe

    https://jmcov.gov.py/cxv.exe

    Hash

    3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec

    2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a

    c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a

    6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb

    f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f

    51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6

    d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66

    447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "http://suporte.ourinhos.sp.gov.br/files/a.exe" or url like "http://suporte.ourinhos.sp.gov.br/files/a.exe" or siteurl like "http://suporte.ourinhos.sp.gov.br/files/a.exe" or domainname like "https://procon.go.gov.br/ComprovantePDF.exe" or url like "https://procon.go.gov.br/ComprovantePDF.exe" or siteurl like "https://procon.go.gov.br/ComprovantePDF.exe" or domainname like "https://www.mrtb.gov.ng/apps/attvpn.vip" or url like "https://www.mrtb.gov.ng/apps/attvpn.vip" or siteurl like "https://www.mrtb.gov.ng/apps/attvpn.vip" or domainname like "https://sit.baer.gob.ve/r.exe" or url like "https://sit.baer.gob.ve/r.exe" or siteurl like "https://sit.baer.gob.ve/r.exe" or domainname like "https://jmcov.gov.py/cxv.exe" or url like "https://jmcov.gov.py/cxv.exe" or siteurl like "https://jmcov.gov.py/cxv.exe" or domainname like "http://suporte.ourinhos.sp.gov.br:443/files/s.exe" or url like "http://suporte.ourinhos.sp.gov.br:443/files/s.exe" or siteurl like "http://suporte.ourinhos.sp.gov.br:443/files/s.exe" or domainname like "https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe" or url like "https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe" or siteurl like "https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe" or domainname like "https://servicos.salto.sp.gov.br/j.jar" or url like "https://servicos.salto.sp.gov.br/j.jar" or siteurl like "https://servicos.salto.sp.gov.br/j.jar" or domainname like "http://credeb.gov.gn/r.zip" or url like "http://credeb.gov.gn/r.zip" or siteurl like "http://credeb.gov.gn/r.zip" or domainname like "http://suporte.ourinhos.sp.gov.br/files/s.zip" or url like "http://suporte.ourinhos.sp.gov.br/files/s.zip" or siteurl like "http://suporte.ourinhos.sp.gov.br/files/s.zip" or domainname like "https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe" or url like "https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe" or siteurl like "https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe" or domainname like "https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe" or url like "https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe" or siteurl like "https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe" or domainname like "https://suporte.camaratunapolis.sc.gov.br/ti/1.exe" or url like "https://suporte.camaratunapolis.sc.gov.br/ti/1.exe" or siteurl like "https://suporte.camaratunapolis.sc.gov.br/ti/1.exe" or domainname like "https://minacu.go.gov.br/ComprovantePDF.exe" or url like "https://minacu.go.gov.br/ComprovantePDF.exe" or siteurl like "https://minacu.go.gov.br/ComprovantePDF.exe" or domainname like "http://gcm.setelagoas.mg.gov.br/files/notepadd.exe" or url like "http://gcm.setelagoas.mg.gov.br/files/notepadd.exe" or siteurl like "http://gcm.setelagoas.mg.gov.br/files/notepadd.exe" or domainname like "https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip" or url like "https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip" or siteurl like "https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip" or domainname like "http://gcm.setelagoas.mg.gov.br/files/tes.exe" or url like "http://gcm.setelagoas.mg.gov.br/files/tes.exe" or siteurl like "http://gcm.setelagoas.mg.gov.br/files/tes.exe" or domainname like "http://gcm.setelagoas.mg.gov.br/files/ti.zip" or url like "http://gcm.setelagoas.mg.gov.br/files/ti.zip" or siteurl like "http://gcm.setelagoas.mg.gov.br/files/ti.zip" or domainname like "dontpad.com" or url like "dontpad.com" or siteurl like "dontpad.com" or domainname like "https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe" or url like "https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe" or siteurl like "https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe"

    Detection Query 2 :

    sha256hash IN ("f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f","51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6","2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a","d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66","447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8","3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec","6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb","c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a")

    Reference:    

    https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil                                         


    Tags

    Threat ActorBrazilFinancial ServicesCommercial FacilitiesExfiltrationAI

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags