BREEZE COMET Threat Group Targets Financial Systems Using Stolen mTLS Credentials
A high-severity threat actor tracked as BREEZE COMET, linked to group UNC5669, has been targeting Brazilian and global financial institutions by breaching core payment systems through multiple intrusion vectors. Attackers gain initial access via password spraying, vishing calls impersonating IT support, or unauthorized hardware connections, with vulnerable JBoss AS instances also exploited. Once inside, the group uses custom backdoors, XWORM, RMM tools, and a reverse SOCKS5 tunnel called COBALTSPIN to move laterally and harvest high-privileged accounts and mTLS credentials from Active Directory and cloud environments. These stolen credentials are then abused to authenticate fraudulent payment instructions across platforms including Pix, Boleto, and STR, with hundreds of unauthorized transactions reported within 24 to 48 hours of gaining access to financial applications. Research from Google Threat Intelligence Group and Axur also flagged potential insider recruitment attempts, though no confirmed insider-led intrusion has been established.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in