AI Weekly Malaysia

Back to items Summaries

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

ID
22483
Status
summarized
Published
09 Sep 2026, 12:20 AM
Fetched
09 Sep 2026, 2:49 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
09 Sep 2026, 2:53 AM
Tags
Audience
developersai_agent_users

What happened

CrowdStrike has identified a previously undocumented threat actor called Slim Spider targeting Brazilian financial institutions since at least March 2026, focusing on stealing cryptocurrency custody secrets and instant payment credentials. The group used custom Bash scripts to query cloud instance metadata for temporary credentials, enumerated secrets from cloud credential managers, and used Foundry's 'cast' tool to derive Ethereum wallet addresses from stolen private keys. They also compromised Azure DevOps pipelines to deploy implants across a Kubernetes cluster, including backdoors named to impersonate Brazil's SPI payment system.

Why it matters

The attack chain—abusing cloud instance metadata for credential theft, then pivoting through Azure DevOps pipelines to compromise Kubernetes clusters—is a generalizable pattern any team using cloud CI/CD should harden against. If you run Azure DevOps pipelines or Kubernetes in cloud environments, verify that your cloud metadata service requires IMDSv2 (or equivalent), audit which identities can trigger pipelines, and check that pipeline service accounts don't have broad Kubernetes RBAC permissions.

Discussion angle

The metadata-service-to-CI/CD-pipeline-to-Kubernetes pivot is the real takeaway—discuss whether your own Azure DevOps or GitHub Actions pipelines could be weaponized the same way if one credential leaks.

Top