← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 1, 2026 · 14:00via Mandiant / Google TI

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Brief

Introduction

Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.

This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064 . In this blog, we detail BREEZE COMET’s tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat.

Read more on Mandiant / Google TI