Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Summary
BREEZE COMET is a financially motivated threat actor targeting Brazilian banks, payment processors, and fintech companies since 2024 to conduct fraudulent transfers through banking systems and payment APIs (interfaces that let software communicate with payment services). The group uses custom malware, compromised government websites for initial access and command and control (C2, the attacker's remote communication channel with infected systems), and generative AI to develop attacks, with recent activity suggesting expansion into other Latin American and African countries.
Classification
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/
First tracked: September 1, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 75%