Introduction: BREEZE COMET Malware — Why It Matters
BREEZE COMET Malware is highlighting a growing threat to financial infrastructure after Google Threat Intelligence Group (GTIG) and Mandiant detailed campaigns targeting Brazilian financial services, retail, and eCommerce organizations. The financially motivated group, formerly tracked as UNC5669, reportedly uses customized malware and generative AI to reach systems capable of processing legitimate financial transactions.
BREEZE COMET Malware is particularly significant because attackers are not simply trying to steal banking credentials. According to Google, BREEZE COMET seeks trusted access to banking software, APIs and payment infrastructure, including Pix, STR and Boleto-related systems, to conduct fraudulent transfers.
Who Is BREEZE COMET?
BREEZE COMET Malware involves a financially motivated threat actor tracked by Google Threat Intelligence Group and Mandiant. The group was previously tracked as UNC5669 and has focused on compromising organizations that have the permissions and connectivity needed to initiate financial transactions.
Its activity reportedly began affecting Brazilian financial organizations in 2024. Researchers also identified infrastructure and activity that could indicate an expansion toward other countries in Latin America and Africa.
BREEZE COMET Malware: Technical Breakdown
Timeline of Events
The reported campaign has evolved through several stages:
- 2024: BREEZE COMET relied on password spraying, voice phishing and commercial remote-management tools to establish access.
- 2025: The group reportedly began abusing compromised government websites, rogue hardware devices and additional malware to gain or maintain footholds.
- 2025–2026: Researchers identified a broader custom malware ecosystem and evidence that generative AI was being used to accelerate operational scripting.
- Final stage: After reaching privileged financial environments, attackers reportedly executed fraudulent transactions through legitimate systems.
What Systems Were Targeted?
The campaign reportedly focused on organizations with access to:
- Banking software and financial APIs
- Pix payment infrastructure
- STR, Brazil’s Reserves Transfer System
- Boleto-related payment systems
- Active Directory and cloud environments
- CI/CD systems containing credentials and API keys
- Internal networks connecting financial applications
Brazil’s central bank describes Pix as an instant payment and transfer system used through participating financial institutions.
Malware and AI-Assisted Operations
BREEZE COMET Malware has been linked to several custom tools, including:
- REALBREEZE: Used for LDAP brute-forcing and Active Directory discovery.
- COBALTSPIN: A Rust-based network tunneler used to reach internal financial infrastructure.
- LIGHTPAINT: A Java backdoor designed to establish persistent access.
- MILDFROST: A Java-based backdoor capable of covert DNS tunneling.
- KICKPLATE: A Nim-based backdoor used for persistence and payload delivery.
- BOATBEAM: A Go-based backdoor designed to disguise command-and-control traffic.
Google also reported evidence that large language models helped accelerate custom scripting for reconnaissance, credential validation, deployment, victim-specific pivoting and data extraction. This does not mean AI independently conducted the attacks; rather, it reportedly helped the operators develop and adapt tooling faster.
Potential Risks & Impact
Financial Risk
BREEZE COMET Malware poses a serious risk of unauthorized movement of money through legitimate financial channels. In one reported case, forensic evidence indicated that two waves of hundreds of fraudulent transactions occurred within 24–48 hours after the attackers established the necessary access.
Business and Reputational Risk
Organizations that depend on payment APIs and interconnected banking infrastructure could face operational disruption, financial losses and reputational damage if attackers obtain trusted accounts or credentials.
Regulatory and Compliance Risk
A compromise involving payment systems can also create significant security, fraud-monitoring and incident-response obligations. Organizations should therefore treat privileged access to financial applications as a high-value security boundary.
Official Response / Statement
The detailed findings come from Google Threat Intelligence Group and Mandiant’s September 1, 2026 threat intelligence report. The researchers described BREEZE COMET as an active and developing threat and published mitigation recommendations and detection information for organizations defending financial environments.
Google Cloud’s BREEZE COMET threat intelligence report
Industry Context: Why AI-Assisted Financial Attacks Matter
BREEZE COMET Malware demonstrates a shift from conventional credential theft toward direct compromise of organizations that can initiate financial transactions. Attackers reportedly combine social engineering, compromised infrastructure, custom malware, stolen credentials and network tunneling to reach payment systems.
This makes the incident relevant beyond Brazil. Organizations can review similar cyber incidents and financial-sector threats through CyberNexora’s Cyber Incidents category.
The use of generative AI adds another layer. Faster script development can allow threat actors to modify reconnaissance and deployment workflows more quickly, potentially reducing the time defenders have to identify and contain an intrusion.
How to Protect Your Organization
Organizations handling financial transactions should consider these measures:
- Enforce phishing-resistant MFA for VPN, SaaS, administrative and other externally accessible accounts.
- Block unauthorized RMM tools and monitor for portable remote-access software.
- Deploy network access control at branch and retail locations to prevent rogue devices from joining internal networks.
- Segment financial systems from ordinary workstations and restrict unnecessary SMB and RDP connections.
- Protect secrets and certificates by removing plaintext credentials from source code and CI/CD environments.
- Monitor PowerShell activity using Script Block Logging, AMSI and appropriate execution controls.
- Restrict cloud and Kubernetes permissions using least-privilege identities and strong workload isolation.
- Monitor financial APIs closely for unusual transaction patterns, privileged-account activity and unexpected authentication behavior.
Organizations can also review practical security guidance through CyberNexora’s Learn & Protect resources.
Indicators of Compromise (IoCs)
Google’s investigation identified multiple file and network indicators associated with the campaign. Organizations should validate these indicators against the original threat intelligence report before adding them to production detection rules.
Notable indicators include:
dontpad[.]com— reportedly used for data exfiltration.- SHA-256:
3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec— COBALTSPIN. - SHA-256:
2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a— REALBREEZE. - SHA-256:
c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a— MILDFROST. - SHA-256:
6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb— BOATBEAM.
Additional hashes, compromised staging domains and YARA rules are available in Google’s detailed report.
Key Takeaways
- BREEZE COMET Malware reportedly targets organizations with trusted access to Brazilian financial infrastructure.
- The group has been linked to multiple custom malware families.
- Generative AI reportedly helped accelerate reconnaissance, credential validation and deployment activities.
- The campaign demonstrates the risk of compromising legitimate accounts instead of directly attacking payment systems.
- Financial organizations should prioritize identity security, segmentation, API monitoring and rapid detection.
Conclusion: BREEZE COMET Malware and What Happens Next
BREEZE COMET Malware shows how financially motivated attackers can combine social engineering, custom malware and AI-assisted development to move from an initial foothold toward legitimate payment infrastructure. The reported use of Pix, STR and other financial systems makes trusted identities and privileged access especially important security controls.
Organizations facing BREEZE COMET Malware should watch for unusual remote-management activity, rogue devices, unexpected access to financial APIs, suspicious PowerShell execution and abnormal transactions.
For additional cybersecurity guidance, readers can explore CyberNexora’s Learn & Protect category.
Frequently Asked Questions(FAQs)
BREEZE COMET Malware refers to the reported malware-enabled campaign conducted by the financially motivated BREEZE COMET group against Brazilian financial and related organizations. Google tracks the actor as BREEZE COMET, formerly UNC5669.
BREEZE COMET reportedly targets banks, payment processors, retailers, eCommerce organizations, fintechs and other entities with access to financial software and payment infrastructure.
Reported techniques include password spraying, voice phishing, compromised websites, rogue hardware devices and exploitation of vulnerable infrastructure. The group has also used legitimate remote-management software to establish access.
Researchers reported that large language models helped accelerate custom scripts for reconnaissance, credential validation, deployment, pivoting and data extraction. The reported use primarily concerns speeding up development and operational workflows.
The campaign reportedly targets systems and organizations connected to Pix, STR and Boleto, as well as banking software and financial APIs.
Organizations should strengthen MFA, block unauthorized RMM software, segment financial networks, secure cloud and CI/CD credentials, monitor privileged accounts and detect abnormal API and transaction activity.
