Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-01 and was added to the RWP archive on 2026-09-07.

Daily Top · Ransomware & Cybercrime

Breeze Comet does not encrypt Brazilian banks — it sends Pix as the bank

GTIG/Mandiant 1 September 2026 — UNC5669, now BREEZE COMET, lives in Pix/STR/Boleto rails. Hundreds of fraudulent transfers in 24–48 hours after payment-app access. Overlap with Plump Spider / SHADOW-AETHER-064, not a merge.

RWP Ventures · 2026-09-07 · event 2026-09-01 · 1 min read · priority 8.3

Bottom line up front

CONFIRMED 1 September 2026 GTIG and Mandiant named BREEZE COMET (ex-UNC5669), tracked since at least 2024, as a Brazil-focused financial crime actor that manipulates payment software rather than running ransomware. Targets: banks, processors, retail, exchanges, fintech, banking-software vendors — anyone who can originate Pix, STR, or Boleto. Requirements GTIG listed: RSFN access via a participant; mTLS credentials that sign transactional orders; multiple AD/cloud accounts; knowledge of the victim's anti-fraud and transfer procedures.

In at least one Mandiant-backed case: privileged access + COBALTSPIN into core financial apps, then two waves totaling hundreds of fraudulent transactions inside 24–48 hours, tens of thousands of USD equivalent. Mid-2025: compromised small Brazilian municipal sites staging RMM, fake tax PDFs (ComprovantePDF.exe), XWORM. Axur: vishing and insider-recruit attempts. CrowdStrike/Trend overlap names (Plump Spider, SHADOW-AETHER-064) are activity overlap, not GTIG attribution.

ASSESSED This is payment-rail abuse. If you only hunt encryptors you will miss it.

What happened

Custom malware plus trusted websites for access, C2, and API talk. Infrastructure hints at LATAM/Africa expansion — intent, not a confirmed second-country heist in the GTIG post.

Why it matters

Instant-payment systems turn a domain admin into a wire room. U.S. firms with Brazil ops inherit this, not just Banco do Brasil.

What is confirmed vs not

CONFIRMED GTIG targeting model, one quantified heist, municipal staging.

REPORTED Dark Reading/THN retellings.

UNKNOWN public victim names.

What defenders should do

  1. Out-of-band controls on Pix/STR originators — mTLS keys are crown jewels.
  2. Municipal/small-gov hosting is staging. Treat Brazilian .gov sites as untrusted for downloads.
  3. Vishing/insider as the IT door, not a CVE.

RWP assessment

Confidence: High on GTIG's mechanics. Do not file this under “ransomware in manufacturing.”

Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-01 and was added to the RWP archive on 2026-09-07.

Sources

  1. GTIG — BREEZE COMET targets Brazil
  2. The Hacker News — Hundreds of fraudulent Pix/STR transactions
  3. Dark Reading — Breeze Comet Brazilian financial systems