BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers
Brief
Brazilian banks and payment companies are facing a more direct form of cybercrime. BREEZE COMET, a financially motivated group formerly tracked as UNC5669, targets the systems that move money instead of individual account holders.
Its goal is to gain trusted access and submit fraudulent transfers through legitimate financial channels. The campaign has affected financial services, retail and eCommerce organizations since 2024.
Attackers have used password spraying, calls impersonating IT support, compromised public websites and rogue devices connected to retail networks. Analysts at Google Cloud identified the group’s use of custom malware alongside generative AI.
This combination helps operators search networks, test stolen credentials, move between systems and prepare data theft faster. It gives a conventional intrusion a clearer route to payment fraud.
