Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Threat Intelligence
  5. Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Scheduled Pinned Locked Moved Threat Intelligence
google
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Brazilian financial services, retail, and e-commerce organizations have been under attack since 2024 by a financially motivated threat actor known as Breeze Comet (formerly UNC5669). Researchers from Google Threat Intelligence Group (GTIG) and Mandiant characterize the group as specialized in tampering with payment systems and banking software within Brazil to enable unauthorized transfers.

    The campaign focuses on manipulating transaction flows at the point of sale or within backend banking integrations. While the exact initial access vector is not detailed in public reporting, the attackers demonstrate deep familiarity with Brazilian payment infrastructure and compliance frameworks. Key operational details disclosed so far include:

    • Activity concentrated exclusively on Brazilian entities across financial services, retail, and e-commerce verticals.
    • The ability to execute hundreds of fraudulent transactions per campaign, indicating automated or semi-automated exploitation of payment logic.
    • Targeting of banking software and payment gateways rather than traditional endpoint malware.
    • A clear financial motive, with no evidence of espionage or data theft beyond what is necessary for payment fraud.

    Breeze Comet’s tradecraft suggests a deliberate focus on the unique characteristics of Brazilian banking, including Pix instant payments and local card processing rules. The group appears to have evaded widespread detection by operating within legitimate transaction volumes, making anomaly-based monitoring particularly challenging.

    Affected organizations are advised to review payment gateway logs for irregular sequence patterns and to validate any changes to bank routing configurations.

    Source: The Hacker News

    Given the heavy reliance on Pix and local payment rails, how is your organization detecting anomalies in high-frequency transaction streams without drowning in false positives?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World