Slim Spider
First seen Sep 9, 2026 · Updated Sep 9, 2026
CrowdStrike has identified a new financially motivated threat actor, dubbed Slim Spider, targeting Brazilian financial institutions since at least March 2026. The group demonstrates deep knowledge of Brazilian financial infrastructure, including instant payment systems, and has been observed stealing crypto custody secrets from a targeted institution.
Technical Analysis
Slim Spider appears to be a financially motivated, Brazil-focused activity cluster with specialized knowledge of local instant payment rails (likely Pix) and crypto custody workflows, suggesting reconnaissance and possibly insider-level familiarity with target environments. The reporting indicates theft of crypto custody secrets, which likely involves credential harvesting, session token theft, or targeted social engineering against personnel with access to custody key material or approval workflows. No specific malware families, CVEs, or technical exploitation chains are detailed in the available reporting, limiting deeper technical attribution at this time. Given the financial sector focus and custody-secret theft, this activity could plausibly compromise API keys, service credentials, or custody-related secrets that AI agents or automated trading/settlement bots rely on for transaction authorization, making agent-integrated financial systems a downstream risk if credential reuse or shared secrets exist.
Affected Systems
Brazilian financial institution networks, instant payment (Pix-related) infrastructure, crypto custody platforms and associated credential/secret storage systems
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) disclosed in available reporting
Remediation Steps
- 1
Rotate custody and payment credentials
Immediately rotate API keys, private keys, and access tokens associated with crypto custody and instant payment systems that may have been exposed.
- 2
Enhance monitoring on financial infrastructure
Deploy heightened monitoring for anomalous access to custody platforms, Pix transaction systems, and privileged accounts within financial institutions.
- 3
Enforce MFA and least privilege
Require hardware-backed multi-factor authentication for custody and payment system access, and review privilege levels for accounts with custody secret access.
- 4
Audit third-party and agent credential usage
Identify any AI agents, bots, or automated systems that use shared or long-lived credentials for payment/custody operations and isolate or rotate those secrets.
- 5
Engage threat intelligence sharing
Coordinate with CrowdStrike and Brazilian financial sector ISACs to obtain updated IOCs and TTPs as investigation progresses.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.