← Home
CYBERSECURITY

Breeze Comet Targets Brazilian Payment Systems for Massive Fraud

September 8, 2026 Priya Nair

How Attackers Manipulate Local Transaction Flows

Since 2024, a financially motivated cybercriminal group known as Breeze Comet has targeted Brazil’s financial sector. This threat actor, previously identified as UNC5669, focuses on payment systems within retail and e-commerce firms. The group executes hundreds of fraudulent transactions using sophisticated manipulation techniques. Security experts describe their operations as highly specialized and damaging to local businesses.

The attackers exploit vulnerabilities in how Brazilian companies process digital payments. They inject malicious code into legitimate transaction flows to divert funds. This method allows them to move money quickly before detection systems trigger alerts. The group demonstrates deep knowledge of local banking infrastructure and software dependencies. Their actions create significant financial losses for affected organizations across the country.

Breeze Comet specializes in manipulating payment gateways used by major retailers. The group identifies specific software components that handle customer checkout processes. They deploy custom malware designed to interact directly with these components. Once installed, the malware alters transaction data in real-time. This modification redirects payments to accounts controlled by the attackers. The process remains invisible to end-users during the purchase.

Why Financial Institutions Face Heightened Risk

Security researchers note that the group maintains persistent access to compromised networks. They use this access to monitor transaction volumes and timing. Attacks often coincide with peak shopping periods or large promotional events. This timing maximizes the number of fraudulent transactions executed. The malware can run for weeks without triggering standard antivirus alerts. It blends seamlessly with normal application behavior to evade detection.

Brazilian financial institutions face unique challenges due to rapid digital adoption. Many smaller e-commerce platforms rely on third-party payment processors. These integrations create additional attack surfaces for threat actors like Breeze Comet. The group targets these integration points rather than core banking systems. This approach allows them to bypass traditional perimeter defenses.

Mandiant and Google Threat Intelligence Group teams have tracked the group’s evolution. They observe a shift toward more automated fraud execution. The attackers now use scripts to generate thousands of small transactions. This volume-based strategy reduces the chance of any single transaction being flagged. The cumulative effect drains significant capital from merchant accounts.

Frequently Asked Questions

Who is Breeze Comet? Breeze Comet is a financially motivated threat actor formerly known as UNC5669. The group has been active since 2024 targeting Brazilian businesses. They specialize in manipulating payment systems to steal funds.

How do they execute fraudulent transactions? They deploy malware that modifies data within legitimate payment gateways. This allows them to redirect funds to external accounts. The process occurs during standard customer checkout sessions.

Which sectors are most affected? Retail and e-commerce organizations in Brazil face the highest risk. Financial services providers also report increased incidents. The group targets systems that handle high-volume digital payments.

Read full article on Tech Site News →