AI Weekly Malaysia

Back to items Summaries

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

ID
20374
Status
summarized
Published
02 Sep 2026, 1:19 AM
Fetched
02 Sep 2026, 3:11 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
02 Sep 2026, 3:14 AM
Tags
Audience
developerssaas_founders

What happened

A financially motivated threat actor dubbed Breeze Comet (also tracked as UNC5669, Plump Spider, SHADOW-AETHER-064) has been targeting Brazilian financial services, retail, and e-commerce since 2023, manipulating payment systems like Pix, STR, and Boleto to conduct fraudulent transfers. Initial access is gained via password spraying, WhatsApp-based IT support impersonation leading victims to install AnyDesk and PowerShell recon scripts, and exploitation of vulnerable JBoss AS servers to deploy web shells and proxy tools like Chisel. At least one heist netted tens of thousands of USD, and Google's GTIG notes signs the group may expand beyond Brazil.

Why it matters

For Malaysian fintech and payment-API builders, the attack chain is a concrete playbook to defend against: social engineering via consumer messaging apps (WhatsApp) to install RMM tools, targeting of payment APIs and banking software specifically, and exploitation of outdated app servers (JBoss AS). If your team runs payment APIs or handles transaction permissions, review whether your staff would fall for a WhatsApp 'IT support' request to install AnyDesk or run a PowerShell script, and patch any legacy JBoss instances exposed to the internet.

Discussion angle

The attack relies heavily on social engineering via WhatsApp to get employees to install RMM tools — worth discussing whether Malaysian fintech teams have any guardrails against this, given how common WhatsApp is for business communication locally.

Top