Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Google renames a Brazilian payment-fraud actor

2 min read
12:09UTC

Google Threat Intelligence Group named BREEZE COMET on 1 September, an actor it says it previously tracked as UNC5669 and now assesses as working against Brazilian payment infrastructure.

TechnologyDeveloping
Key takeaway

GTIG merged three tracked clusters into BREEZE COMET, and no other firm can check the merge.

Google Threat Intelligence Group, the threat-research arm of Google Cloud, named BREEZE COMET on 1 September, an actor GTIG says it previously tracked as UNC5669 and now assesses as a financially motivated group working against Brazilian payment infrastructure 1. Threat-intelligence firms assign their own labels to the activity they observe, so the same crew can carry a different name at every vendor, and a rename inside one firm is a housekeeping decision the rest of the industry then adopts.

GTIG says BREEZE COMET targets banks, payment processors, retailers, exchanges, fintechs and banking-software providers able to transact through Pix, Brazil's instant-payment system, STR, the country's real-time gross settlement system, and Boleto, the payment slip Brazilians use to settle bills. GTIG says it observed a Rust-based tunneller it calls COBALTSPIN holding access to financial application programming interface infrastructure through a reverse SOCKS5 proxy over WebSocket, and reports at least one completed heist worth tens of thousands of US dollars.

Hold the merge at arm's length. GTIG also says its BREEZE COMET activity overlaps with operations other firms have reported as Plump Spider and SHADOW-AETHER-064. Nobody outside Google can test that, a second write-up of the same post is not a second source, and a name that enters circulation this way tends to stay in it.

This beat watched the same mechanism run in the opposite direction in July, when a research firm hedged the attribution on a hotel router campaign and a technology publisher named a Russian state unit anyway . A label travels faster than the confidence attached to it. Treat the three-cluster unification as GTIG's reading rather than a settled identity, and cite it that way in anything a fraud team acts on.

Deep Analysis

In plain English

Google's threat intelligence team gave a name, BREEZE COMET, to a group of hackers it has been tracking under a different code name until now. The group targets Brazil's payment systems, including Pix, the instant bank-transfer system most Brazilians use. Security companies often give the same hacking group different names because they discover and study it separately. Google says this group's activity looks similar to ones two other firms track under their own names.

Deep Analysis
Root Causes

Pix, Brazil's instant-payment rail, settles transactions in seconds with no reversal window once confirmed, which makes payment-infrastructure intrusions immediately monetisable in a way slower settlement rails are not.

A Rust-based tunneller resists the memory-safety tooling and signature detection built for the C and C++ malware most existing endpoint defences were tuned against, which is part of why the language choice recurs across newer financially motivated tooling.

First Reported In

Update #13 · Four privileged platforms under live attack

Google Threat Intelligence Group· 5 Sept 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.