
Breeze Comet Compromises mTLS Credentials and RSFN Access for Pix Fraud in Brazil
Breeze Comet has shifted Brazilian financial fraud from social engineering to direct manipulation of Pix and STR APIs using stolen mTLS credentials. Multiple vendors confirm the actor’s Brazilian origin, custom tooling stack, and infrastructure expansion signals. The activity exposes systemic gaps in how payment-system access is authenticated and monitored.
Breeze Comet gains initial access through password spraying and vishing campaigns that trick targets into installing AnyDesk or running PowerShell scripts delivered via WhatsApp. Once inside, the group deploys web shells on exposed JBoss servers, stages tooling on compromised Brazilian government sites, and uses REALBREEZE for LDAP brute-forcing plus Impacket and ADRecon for lateral movement. The actor specifically seeks entities already connected to the National Financial System Network to obtain the four prerequisites for successful fraud: RSFN connectivity, mTLS keys, Active Directory credentials, and procedural knowledge of anti-fraud controls.
Mandiant and GTIG reporting documents the use of COBALTSPIN routing malware and custom infostealers masquerading as tax documents, while Axur traced a November 2025 campaign that pivoted from retail networks via rogue hardware to internal payment APIs. CrowdStrike and Trend Micro track the same cluster as Plump Spider and SHADOW-AETHER-064, confirming operations run from Brazil with infrastructure staging observed in Nigeria, Paraguay, Ghana, and Venezuela.
The pattern reveals a shift from opportunistic access to deliberate targeting of payment processors and banking software vendors that hold the technical keys to high-volume transfers. This mirrors earlier Latin American groups that monetized direct API abuse rather than carding or BEC, but Breeze Comet’s reuse of trusted domains and Rust-based tooling indicates faster iteration and lower detection rates.
Payment processors must now assume that any entity with RSFN or Pix API access is a high-value target; monitoring for anomalous mTLS usage and RDP sessions from internal segments will be required to close the window before the next campaign expands into additional African and Latin American corridors.
GTIG: Breeze Comet infrastructure will appear in at least three new African countries by March 2026.
Sources (3)
- [1]Google Threat Intelligence Group Breeze Comet Analysis(https://cloud.google.com/blog/topics/threat-intelligence/breeze-comet)
- [2]Axur November 2025 Incident Report(https://www.axur.com/blog/breeze-comet-whatsapp-campaign)
- [3]CrowdStrike Plump Spider Intelligence Brief(https://www.crowdstrike.com/blog/plump-spider-brazil-payment-fraud/)