Google Threat Intelligence Group, the threat-research arm of Google Cloud, named BREEZE COMET on 1 September, an actor GTIG says it previously tracked as UNC5669 and now assesses as a financially motivated group working against Brazilian payment infrastructure 1. Threat-intelligence firms assign their own labels to the activity they observe, so the same crew can carry a different name at every vendor, and a rename inside one firm is a housekeeping decision the rest of the industry then adopts.
GTIG says BREEZE COMET targets banks, payment processors, retailers, exchanges, fintechs and banking-software providers able to transact through Pix, Brazil's instant-payment system, STR, the country's real-time gross settlement system, and Boleto, the payment slip Brazilians use to settle bills. GTIG says it observed a Rust-based tunneller it calls COBALTSPIN holding access to financial application programming interface infrastructure through a reverse SOCKS5 proxy over WebSocket, and reports at least one completed heist worth tens of thousands of US dollars.
Hold the merge at arm's length. GTIG also says its BREEZE COMET activity overlaps with operations other firms have reported as Plump Spider and SHADOW-AETHER-064. Nobody outside Google can test that, a second write-up of the same post is not a second source, and a name that enters circulation this way tends to stay in it.
This beat watched the same mechanism run in the opposite direction in July, when a research firm hedged the attribution on a hotel router campaign and a technology publisher named a Russian state unit anyway . A label travels faster than the confidence attached to it. Treat the three-cluster unification as GTIG's reading rather than a settled identity, and cite it that way in anything a fraud team acts on.
