Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
- ID
- 22483
- Status
- summarized
- Published
- 09 Sep 2026, 12:20 AM
- Fetched
- 09 Sep 2026, 2:49 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 09 Sep 2026, 2:53 AM
- Tags
- Audience
- developersai_agent_users
What happened
CrowdStrike has identified a previously undocumented threat actor called Slim Spider targeting Brazilian financial institutions since at least March 2026, focusing on stealing cryptocurrency custody secrets and instant payment credentials. The group used custom Bash scripts to query cloud instance metadata for temporary credentials, enumerated secrets from cloud credential managers, and used Foundry's 'cast' tool to derive Ethereum wallet addresses from stolen private keys. They also compromised Azure DevOps pipelines to deploy implants across a Kubernetes cluster, including backdoors named to impersonate Brazil's SPI payment system.
Why it matters
The attack chain—abusing cloud instance metadata for credential theft, then pivoting through Azure DevOps pipelines to compromise Kubernetes clusters—is a generalizable pattern any team using cloud CI/CD should harden against. If you run Azure DevOps pipelines or Kubernetes in cloud environments, verify that your cloud metadata service requires IMDSv2 (or equivalent), audit which identities can trigger pipelines, and check that pipeline service accounts don't have broad Kubernetes RBAC permissions.
Discussion angle
The metadata-service-to-CI/CD-pipeline-to-Kubernetes pivot is the real takeaway—discuss whether your own Azure DevOps or GitHub Actions pipelines could be weaponized the same way if one credential leaks.