Date: 09/01/2026
Severity: High
Summary
BREEZE COMET (UNC5669) is a financially motivated threat actor targeting Brazilian banks, fintechs, retailers, exchanges, and payment providers to manipulate banking software, APIs, and payment systems such as Pix, STR, and Boleto for fraudulent transfers. The group uses custom malware, compromised trusted websites, persistent access, and C2 infrastructure for reconnaissance, lateral movement, persistence, and exfiltration, while evidence of generative AI-assisted malware development suggests its operations may become faster and more sophisticated.
Indicators of Compromise (IOC) List
Domains/URLs | dontpad.com https://procon.go.gov.br/ComprovantePDF.exe https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe http://gcm.setelagoas.mg.gov.br/files/ti.zip http://gcm.setelagoas.mg.gov.br/files/notepadd.exe http://gcm.setelagoas.mg.gov.br/files/tes.exe https://minacu.go.gov.br/ComprovantePDF.exe https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip https://suporte.camaratunapolis.sc.gov.br/ti/1.exe https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe http://suporte.ourinhos.sp.gov.br/files/s.zip http://suporte.ourinhos.sp.gov.br:443/files/s.exe http://suporte.ourinhos.sp.gov.br/files/a.exe https://servicos.salto.sp.gov.br/j.jar https://www.mrtb.gov.ng/apps/attvpn.vip http://credeb.gov.gn/r.zip https://sit.baer.gob.ve/r.exe https://jmcov.gov.py/cxv.exe |
Hash | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec
2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a
c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a
6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb
f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f
51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6
d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66
447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "http://suporte.ourinhos.sp.gov.br/files/a.exe" or url like "http://suporte.ourinhos.sp.gov.br/files/a.exe" or siteurl like "http://suporte.ourinhos.sp.gov.br/files/a.exe" or domainname like "https://procon.go.gov.br/ComprovantePDF.exe" or url like "https://procon.go.gov.br/ComprovantePDF.exe" or siteurl like "https://procon.go.gov.br/ComprovantePDF.exe" or domainname like "https://www.mrtb.gov.ng/apps/attvpn.vip" or url like "https://www.mrtb.gov.ng/apps/attvpn.vip" or siteurl like "https://www.mrtb.gov.ng/apps/attvpn.vip" or domainname like "https://sit.baer.gob.ve/r.exe" or url like "https://sit.baer.gob.ve/r.exe" or siteurl like "https://sit.baer.gob.ve/r.exe" or domainname like "https://jmcov.gov.py/cxv.exe" or url like "https://jmcov.gov.py/cxv.exe" or siteurl like "https://jmcov.gov.py/cxv.exe" or domainname like "http://suporte.ourinhos.sp.gov.br:443/files/s.exe" or url like "http://suporte.ourinhos.sp.gov.br:443/files/s.exe" or siteurl like "http://suporte.ourinhos.sp.gov.br:443/files/s.exe" or domainname like "https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe" or url like "https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe" or siteurl like "https://tisup.camaratunapolis.sc.gov.br/SoftEther.exe" or domainname like "https://servicos.salto.sp.gov.br/j.jar" or url like "https://servicos.salto.sp.gov.br/j.jar" or siteurl like "https://servicos.salto.sp.gov.br/j.jar" or domainname like "http://credeb.gov.gn/r.zip" or url like "http://credeb.gov.gn/r.zip" or siteurl like "http://credeb.gov.gn/r.zip" or domainname like "http://suporte.ourinhos.sp.gov.br/files/s.zip" or url like "http://suporte.ourinhos.sp.gov.br/files/s.zip" or siteurl like "http://suporte.ourinhos.sp.gov.br/files/s.zip" or domainname like "https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe" or url like "https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe" or siteurl like "https://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe" or domainname like "https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe" or url like "https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe" or siteurl like "https://conseg.ssp.go.gov.br/ComprovanteBBpix.exe" or domainname like "https://suporte.camaratunapolis.sc.gov.br/ti/1.exe" or url like "https://suporte.camaratunapolis.sc.gov.br/ti/1.exe" or siteurl like "https://suporte.camaratunapolis.sc.gov.br/ti/1.exe" or domainname like "https://minacu.go.gov.br/ComprovantePDF.exe" or url like "https://minacu.go.gov.br/ComprovantePDF.exe" or siteurl like "https://minacu.go.gov.br/ComprovantePDF.exe" or domainname like "http://gcm.setelagoas.mg.gov.br/files/notepadd.exe" or url like "http://gcm.setelagoas.mg.gov.br/files/notepadd.exe" or siteurl like "http://gcm.setelagoas.mg.gov.br/files/notepadd.exe" or domainname like "https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip" or url like "https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip" or siteurl like "https://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip" or domainname like "http://gcm.setelagoas.mg.gov.br/files/tes.exe" or url like "http://gcm.setelagoas.mg.gov.br/files/tes.exe" or siteurl like "http://gcm.setelagoas.mg.gov.br/files/tes.exe" or domainname like "http://gcm.setelagoas.mg.gov.br/files/ti.zip" or url like "http://gcm.setelagoas.mg.gov.br/files/ti.zip" or siteurl like "http://gcm.setelagoas.mg.gov.br/files/ti.zip" or domainname like "dontpad.com" or url like "dontpad.com" or siteurl like "dontpad.com" or domainname like "https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe" or url like "https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe" or siteurl like "https://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe" |
Detection Query 2 : | sha256hash IN ("f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f","51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6","2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a","d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66","447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8","3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec","6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb","c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a")
|
Reference:
https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil