BREEZE COMETBREEZE COMET
Also known as: BREEZE COMET · UNC5669
Known aliases
2
Profile
BREEZE COMET is a financially motivated threat actor targeting Brazilian financial services, retail, and eCommerce organizations through compromised websites, custom malware, and stolen credentials to manipulate payment systems and execute fraudulent transfers. The group employs custom tools such as REALBREEZE, COBALTSPIN, KICKPLATE, MILDFROST, LIGHTPAINT, and BOATBEAM for reconnaissance, lateral movement, persistence, tunneling, and stealth. Forensic evidence indicates that BREEZE COMET has executed waves of fraudulent transactions within 24-48 hours of compromise, likely stealing tens of thousands of USD in assets. The actor has also leveraged generative AI to enhance malware and script development while expanding its infrastructure across Latin America and Africa.
Aliases· 2
BREEZE COMETUNC5669