Google Threat Intelligence Group and Mandiant say Breeze Comet, formerly UNC5669, has been hitting Brazilian financial services, retail, and e-commerce firms since 2024 and has executed hundreds of fraudulent transactions through payment systems such as Pix, STR, and Boleto. The group is built around stealing value from inside the business, not around noisy disruption.
The access path varies, but the payoff is the same: password spraying, IT-helpdesk impersonation, remote-monitoring tools, web shells, and custom malware can all lead into accounts and systems that are allowed to originate transfers. Once the attacker is inside the payment stack, the bank’s customer-facing fraud checks may see a normal internal order rather than a fake login.
For organizations that can approve or initiate settlement through these rails, the exposure sits in payment-switch permissions, mTLS credentials, and back-office APIs, not just on endpoints. That makes the blast radius broader than one compromised account and leaves any trusted internal transfer path carrying systemic risk if attackers inherit it.