Breeze Comet (formerly UNC5669) Brazilian Payment Fraud Campaign
First seen Sep 2, 2026 · Updated Sep 2, 2026
Breeze Comet is a financially motivated threat actor targeting Brazilian financial services, retail, and e-commerce organizations since 2024, specializing in manipulating payment systems and banking software to execute fraudulent transfers. Google Threat Intelligence Group and Mandiant have tracked hundreds of fraudulent transactions attributed to this group, indicating a mature and persistent operation against Brazil's financial ecosystem.
Technical Analysis
Breeze Comet demonstrates specialized knowledge of Brazilian banking and payment infrastructure, suggesting reconnaissance and possible insider knowledge or reverse-engineering of proprietary financial software used by regional institutions. The group's tactics involve manipulating payment systems and banking software rather than solely relying on generic banking trojans, indicating custom tooling tailored to specific transaction processing platforms. GTIG and Mandiant's designation of the group as a distinct UNC (uncategorized) cluster before formal naming implies sustained tracking of unique infrastructure and TTPs across multiple incidents. The reported raw data is limited in technical specifics (no confirmed CVEs, malware hashes, or C2 infrastructure disclosed), which constrains deeper technical attribution at this time. There is no direct evidence of AI agent or LLM tool-use compromise in this campaign; the impact is centered on financial transaction integrity rather than AI infrastructure, so no agent-specific impact is asserted.
Affected Systems
Brazilian banking software and payment processing platforms; financial services, retail, and e-commerce transaction systems operating in Brazil
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) disclosed in available reporting; refer to forthcoming GTIG/Mandiant technical report for indicators
Remediation Steps
- 1
Enhance Transaction Monitoring
Implement anomaly detection on payment transaction systems to flag unusual transfer patterns, velocity, or amounts consistent with fraudulent activity.
- 2
Review Payment Software Integrity
Audit banking and payment processing software for unauthorized modifications, injected code, or manipulated business logic.
- 3
Strengthen Access Controls
Enforce multi-factor authentication and least-privilege access for systems that interface with payment processing and settlement platforms.
- 4
Engage Threat Intelligence Sharing
Coordinate with Brazilian financial sector ISACs and GTIG/Mandiant for updated IOCs and detection signatures as they become available.
- 5
Conduct Incident Response Readiness Review
Ensure incident response plans account for payment fraud scenarios, including rapid transaction reversal and law enforcement coordination.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.