BREEZE COMETBREEZE COMET

Also known as: BREEZE COMET · UNC5669

Known aliases
2

Profile

BREEZE COMET is a financially motivated threat actor targeting Brazilian financial services, retail, and eCommerce organizations through compromised websites, custom malware, and stolen credentials to manipulate payment systems and execute fraudulent transfers. The group employs custom tools such as REALBREEZE, COBALTSPIN, KICKPLATE, MILDFROST, LIGHTPAINT, and BOATBEAM for reconnaissance, lateral movement, persistence, tunneling, and stealth. Forensic evidence indicates that BREEZE COMET has executed waves of fraudulent transactions within 24-48 hours of compromise, likely stealing tens of thousands of USD in assets. The actor has also leveraged generative AI to enhance malware and script development while expanding its infrastructure across Latin America and Africa.

Aliases· 2

BREEZE COMETUNC5669
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.