Slim Spider Chases Cloud Credentials Into Pix Systems
CrowdStrike tied the Brazil-based Slim Spider cluster to multi-stage intrusions against Brazilian financial institutions since at least March 2026, including a late-March attack that targeted cloud credentials, crypto custody secrets, and Pix payment accounts.
The group queried cloud instance metadata to steal temporary credentials, then used those to reach the cloud credential manager, pull stored secrets, and move into Azure DevOps and a managed Kubernetes cluster. CrowdStrike also saw the actors deploy an implant named "spi" to imitate Brazil's Pix payment infrastructure, which shows the compromise was aimed at the cloud control plane as much as any front-end system.
For institutions that let workloads read instance metadata or let pipelines update Kubernetes, the lasting exposure is not a single breached host but the trust chain those credentials unlock: secret stores, DevOps, containers, and the payment systems they can reach.