
Slim Spider March 2026 intrusion exfiltrated Brazilian bank crypto custody keys via cloud metadata scripts and OpenSSL signing
Slim Spider conducted a targeted March 2026 cloud intrusion against Brazilian crypto custody infrastructure using custom scripts and backdoors. Evidence from exposed C2 and CrowdStrike telemetry shows focus on Pix and digital assets with strong operational security. Expansion to additional institutions is probable within months.
CrowdStrike documented the actor deploying MikeDor, a Go backdoor, and the "spi" implant impersonating Brazil's Pix payment system on Kubernetes nodes. The group enumerated secrets via sed-modified scripts, invoked Foundry's cast tool to derive Ethereum addresses from stolen keys, and ran malicious pipelines from compromised Azure DevOps credentials. An exposed C2 panel listed hosts from multiple Brazilian banks and fintechs with exfiltrated archives. Technical traces show deliberate avoidance of third-party libraries through direct OpenSSL cryptographic signing inside Bash and cloud-native metadata queries over sockets. This matches patterns in prior e-crime operations against financial custody but adds Brazil-specific Pix automation panels and Ollama-driven endpoint categorization. No independent technical attribution beyond CrowdStrike's telemetry has confirmed state involvement. The operation reveals recurring targeting of high-value digital asset credentials over generic banking access. Similar clusters have shifted from initial access brokers to direct wallet control within 60 days of cloud foothold. Next indicators will likely appear in Azure activity logs showing anomalous pipeline executions or new NEXUS scanner hits on fintech endpoints. Defenders should prioritize monitoring of cloud credential managers tied to crypto wallets and enforce strict separation between DevOps pipelines and production clusters.
CrowdStrike: Slim Spider will compromise credentials from at least two additional Brazilian fintechs by December 2026
Sources (2)
- [1]Primary Source(https://www.crowdstrike.com/blog/slim-spider-brazil-financial-intrusion-2026)
- [2]Supporting Source(https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html)