← Blog · · df00tech

Breeze Comet (UNC5669) Targets Brazilian Payment Systems in Ongoing Fraud Campaign

security-news campaign

What Happened

Google Threat Intelligence Group (GTIG) and Mandiant have detailed the activity of a financially motivated threat actor tracked as Breeze Comet (formerly designated UNC5669). According to the researchers, the group has been active since 2024 and specializes in manipulating payment systems and banking software in Brazil to execute fraudulent transfers. Reported targeting spans Brazilian financial services, retail, and e-commerce organizations, with hundreds of fraudulent transactions attributed to the actor's operations.

Why It Matters for Defenders

This is a sustained, financially motivated campaign against Brazil's payment ecosystem rather than an opportunistic one-off. Organizations that process or integrate with Brazilian banking and payment rails — financial institutions, retailers, and e-commerce platforms operating in or transacting with Brazil — should treat this as an active threat to fraud-control and payment-integrity systems, not just a general malware concern. Given the actor's apparent focus on manipulating legitimate payment software and transfer mechanisms, standard perimeter and endpoint controls alone may not be sufficient; fraud-detection and transaction-monitoring layers are directly in scope.

What Defenders Should Watch For

  • Anomalous or unauthorized transfer activity originating from systems that interact with payment processing or banking software, particularly patterns consistent with automated or scripted fraudulent transactions.
  • Unexpected modifications to payment application configurations, transaction-routing logic, or banking software components.
  • Unusual authentication or session activity associated with payment-processing accounts and service credentials.
  • Hunting angles: review integrity/change logs for payment and banking applications, correlate transaction anomalies with endpoint or identity telemetry, and validate that fraud-monitoring alerting thresholds account for manipulation of legitimate transfer workflows rather than only external intrusion indicators.
  • Given the specific regional and sectoral focus, Brazilian financial services and retail/e-commerce organizations should prioritize threat-intel sharing with peers and payment-network partners.

Developing Intelligence

Full technical details on Breeze Comet's tooling, infection vectors, and specific abuse techniques were not included in the portion of the report reviewed here. This is net-new intel and the picture may evolve as GTIG/Mandiant publish further findings. For the complete report, see the original source: The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.