Security1 distinct publisher3 min readPublished
Google Threat Intelligence and Mandiant put the Brazilian crew's route to Pix and STR at password spraying plus a fake IT support call, which means the controls that bite here are RMM allow-listing and out-of-band verification of the help desk.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The voice call is the intrusion. Password spraying supplies a working credential, the call supplies the remote session, and after the operator installs AnyDesk the attacker is typing on a trusted endpoint [6]. Axur's November 2025 case ran the same pretext over WhatsApp and finished with the victim executing a PowerShell reconnaissance script, presented as an application update [7]. Neither step involves a flaw in software, and the only entry route Google documents that does is the web shell dropped on vulnerable JBoss AS servers, so exactly one of the two documented routes is patchable [8][2].
Google's four preconditions for a fraudulent transfer say the same thing in the actor's own terms: access to the National Financial System Network through an entity that already holds it, mTLS credentials that can sign transactional payloads to Pix or STR, several accounts across Active Directory and cloud, and an understanding of how the target actually processes transfers and screens fraud [10]. Three of the four are credential and access problems and the fourth is homework [3]. The actor does not need to be an RSFN participant; it needs to be inside one [10].
That is why the AnyDesk install and the help-desk phone line are the control surface. Allow-list remote access binaries and deny by default, because the staging is designed to beat reputation: GTIG describes RMM installers, infostealers dressed as tax or receipt documents, and XWorm hosted on compromised small Brazilian government sites that also serve as C2 [11]. A domain block list does not help when the download comes from a .gov.br host. On the voice side, the verification has to run on a channel the caller did not choose, meaning a callback to a number the employee looks up and a ticket that exists before the install, not after.
Lateral movement is built to survive the hunt for persistence. COBALTSPIN, a Rust tunneler, opens a reverse SOCKS5 proxy over WebSocket and routes traffic between C2 and internal targets through boundary firewalls, which Google notes removes the need for built-in persistence mechanisms that might trigger detection [14][15]. Internal reconnaissance uses Impacket, ADRecon, ADVipscan and a custom LDAP brute-forcer called REALBREEZE against development and cloud environments [13]. In retail, the crew has skipped the network path entirely and plugged rogue hardware into store networks [12].
The attribution is layered, and worth separating. GTIG and Mandiant track Breeze Comet, formerly UNC5669, against Brazilian financial services, retail and e-commerce since 2024 [1]. CrowdStrike's Plump Spider and Trend Micro's SHADOW-AETHER-064 are described as overlapping clusters [4], with CrowdStrike dating the Brazil-based group to September 2023 [5]. That earliest vendor date sits at least four months before the window Google gives [1]. Documented loss so far is at least one heist worth tens of thousands of dollars [3] across hundreds of fraudulent transactions [18].
Ranked by verification strength, evidence, and original report placement.
Google Threat Intelligence Group (GTIG) and Mandiant track a financially motivated actor dubbed Breeze Comet, formerly UNC5669, targeting Brazilian financial services, retail and e-commerce organizations since 2024.
GTIG and Mandiant describe Breeze Comet as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers."
The actor is said to have successfully carried out at least one heist of assets worth tens of thousands of U.S. dollars.
The activity overlaps with clusters tracked by CrowdStrike as Plump Spider and by Trend Micro as SHADOW-AETHER-064.
According to CrowdStrike, the e-crime group operates out of Brazil, has been active since September 2023, and monetizes intrusions by gaining unauthorized access to internal payment systems and carrying out fraudulent transactions.
Initial access to financial entities is accomplished via password spraying and voice calls impersonating IT support teams to persuade targets to install Remote Monitoring and Management tools such as AnyDesk.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Mandiant found 100 high-severity bugs in two days. Plan for the other side doing the same.1 distinct publisher
security
Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 20201 distinct publisher
leadership
UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor, one relay
Every load-carrying detail — the four preconditions for reaching Pix, REALBREEZE, COBALTSPIN's reverse SOCKS5 tunnel, the count of fraudulent transactions — originates with Google Threat Intelligence Group and Mandiant and reaches readers through The Hacker News. CrowdStrike and Trend Micro look like independent confirmation, but the only thing establishing that their clusters are the same crew is Google's own overlap mapping, restated here. The tradecraft is described with the specificity that usually comes from real incident response; it simply has not been checked by anyone outside the vendor.
Money moved, scale withheld
This is not a proof-of-concept: hundreds of transactions were pushed through Brazilian payment rails, one theft of tens of thousands of dollars is asserted as complete, and Axur watched a live help-desk impersonation last November. What is missing is scale — no victim is named, no institution has disclosed a loss, and there is no count of compromised organizations, so real-world impact is established as fact but not as magnitude.
Headline counts, footnote losses
"Hundreds of fraudulent transactions" carries the headline while the only sum anyone will commit to is tens of thousands of dollars from one heist — a gap the reader has to notice unaided. The tradecraft description is, if anything, the sober part; the overreach sits in the forward-looking line about expansion into Latin America and Africa, which rests on a repeated staging pattern in four countries rather than on any observed operation there.
Naming rights as marketing
Four security vendors appear here and each has a commercial reason to be visible: Google and Mandiant retiring an internal designation in favour of a branded actor name, CrowdStrike and Trend Micro holding rival names for what may be the same crew, and Axur supplying the case study that dates the technique. That does not make the research wrong — cross-vendor naming rivalry usually indicates several teams genuinely watching the same activity — but the story is built from material whose publication is itself a demand-generation act, and nothing in the write-up flags that.
Granular but unaudited
Confidence lands mid-range for two opposite reasons. The technical layer is the kind of thing that is hard to fabricate and easy to test — file names, port 443, WebSocket transport, cleared logs — and defenders can act on it immediately. The framing layer is softer: one publisher, one vendor's incident data, no victim confirmation, and a start-date disagreement of at least four months between CrowdStrike and Google that nobody resolves. Trust the tradecraft, hold the scope loosely.