Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
- ID
- 20374
- Status
- summarized
- Published
- 02 Sep 2026, 1:19 AM
- Fetched
- 02 Sep 2026, 3:11 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 02 Sep 2026, 3:14 AM
- Tags
- Audience
- developerssaas_founders
What happened
A financially motivated threat actor dubbed Breeze Comet (also tracked as UNC5669, Plump Spider, SHADOW-AETHER-064) has been targeting Brazilian financial services, retail, and e-commerce since 2023, manipulating payment systems like Pix, STR, and Boleto to conduct fraudulent transfers. Initial access is gained via password spraying, WhatsApp-based IT support impersonation leading victims to install AnyDesk and PowerShell recon scripts, and exploitation of vulnerable JBoss AS servers to deploy web shells and proxy tools like Chisel. At least one heist netted tens of thousands of USD, and Google's GTIG notes signs the group may expand beyond Brazil.
Why it matters
For Malaysian fintech and payment-API builders, the attack chain is a concrete playbook to defend against: social engineering via consumer messaging apps (WhatsApp) to install RMM tools, targeting of payment APIs and banking software specifically, and exploitation of outdated app servers (JBoss AS). If your team runs payment APIs or handles transaction permissions, review whether your staff would fall for a WhatsApp 'IT support' request to install AnyDesk or run a PowerShell script, and patch any legacy JBoss instances exposed to the internet.
Discussion angle
The attack relies heavily on social engineering via WhatsApp to get employees to install RMM tools — worth discussing whether Malaysian fintech teams have any guardrails against this, given how common WhatsApp is for business communication locally.