← Back to all briefings
Cybersecurity 6 min read Published Updated

BREEZE COMET: What Financially Motivated Attacks on Brazil Reveal About Payment-System Security

Google Threat Intelligence Group linked BREEZE COMET to financially motivated operations targeting Brazilian financial institutions and payment ecosystems. The campaign shows how trusted websites, custom malware and payment-system access can combine into direct financial theft.

Reviewed for accuracy by Kodi C.

Cybersecurity pillar illustration for Zeph Tech briefings
Cybersecurity threat, control, and response briefings

Archive coverage note: This Zeph Tech briefing was published on September 27, 2026 and documents a security development from . The historical date in the URL identifies the covered event; it is not a claim that Zeph Tech originally published the page on that date.

Financial cybercrime now targets the systems around payments rather than only stealing consumer passwords. Access to banking software, payment APIs or trusted infrastructure can let an attacker manipulate money movement at scale.

What happened

Google Threat Intelligence Group detailed activity it tracks as BREEZE COMET, a financially motivated threat actor focused on Brazil. The reporting describes operations involving trusted website compromise, custom malware and targeting of financial and payment-system environments.

  • GTIG tracks the actor as financially motivated and focused heavily on Brazilian organizations.
  • The campaign uses compromised legitimate websites and custom tooling as part of infection and access workflows.
  • Financial software and payment-system connectivity are central to the actor's objectives.
  • The activity demonstrates the value of regional threat intelligence because infrastructure, language and financial rails influence attacker tradecraft.

Why defenders should care

Payment environments combine high-value credentials, transaction authority and time-sensitive operations. Attackers who reach trusted financial software may be able to turn a technical compromise into direct monetary loss faster than a conventional data-theft intrusion.

  • Compromised trusted websites can bypass user skepticism and reputation-based controls.
  • Payment APIs and banking software may grant transaction capability rather than only data access.
  • Custom malware can evade commodity signatures and adapt to local environments.
  • Third-party financial integrations can create trust paths that are not visible in a normal endpoint inventory.

Priority response

Organizations should translate this development into a controlled security workflow: identify affected assets and trust relationships, reduce unnecessary exposure, apply the relevant vendor or architecture controls, and verify the outcome with evidence rather than assuming a configuration change was successful.

  1. Map every application and third party that can initiate, approve or modify payment transactions.
  2. Use strong transaction-level authorization so endpoint compromise alone cannot move funds.
  3. Monitor for unusual payment beneficiaries, transaction timing, device context and API-call patterns.
  4. Segment financial administration workstations and restrict their software installation and web access.
  5. Collect regional threat intelligence relevant to the countries, banks and payment platforms the organization actually uses.
  6. Exercise fraud, security and treasury teams together because containment may require both technical and financial actions.

Detection and verification

Combine endpoint indicators with payment telemetry. High-value signals include new beneficiaries, unusual transaction sequences, logins from unexpected devices or regions, API calls outside normal application behavior, credential use immediately after malware alerts, and access to financial applications from newly compromised hosts.

Preserve the telemetry needed to establish a timeline before making disruptive changes when practical. Correlate identity, host, application, cloud and network signals so the team can distinguish a blocked attempt from successful access and can identify follow-on behavior.

Longer-term security lesson

Financial-sector defense cannot stop at malware detection. Transaction authorization, behavioral fraud controls, segregated duties and rapid coordination between security and finance can prevent a technical compromise from becoming an irreversible payment event.

For program owners, the recurring requirement is evidence: know which systems are affected, which owner is accountable, what control was changed, and what proves the residual risk is acceptable. That discipline turns a fast-moving advisory into repeatable security operations.

Questions teams should be able to answer

Is BREEZE COMET primarily an espionage actor?

GTIG characterizes the tracked activity as financially motivated.

Why do trusted websites matter?

Compromised legitimate sites can provide a delivery path that appears more credible to users and may have better reputation than newly created attacker domains.

What is the most important control around payment APIs?

Use narrowly scoped identities and independent transaction authorization so one compromised workstation or credential cannot silently initiate unrestricted payments.

Use the Vulnerability Management Program guide to operationalize urgent security changes, the free cybersecurity risk register to assign residual exposure and treatment ownership, and the Cybersecurity hub for broader defensive guidance.

Scope the operational blast radius

Map the payment path from user workstation to banking software, signing systems, payment APIs, fraud controls and final transaction authorization. The critical question is whether compromise of one endpoint or application can produce a valid transaction without an independent check. Include vendor-managed systems and trusted network paths in the map.

Preserve endpoint and identity telemetry, remote-management activity, payment application logs, API calls, beneficiary changes, hardware security module requests, transaction timing and fraud alerts. Correlate technical compromise with financial activity because the decisive signal may be a validly signed but behaviorally abnormal payment rather than malware alone.

Turn remediation into an auditable control

Use transaction-level controls that are independent of the initiating workstation, segregate duties, restrict remote administration of financial endpoints, protect payment identities and signing workflows, and monitor trusted websites or third parties used in delivery chains. Security, fraud and treasury teams should share a rapid escalation path.

Measure whether the control is improving instead of counting closed tickets. Useful indicators for this topic include new beneficiaries outside normal process; high-value transactions from new device context; payment API identities with broad authority; remote-management tools on finance endpoints; time from security alert to payment hold; and transaction anomalies correlated with endpoint compromise. Review the measures after material architecture changes and after incidents so the program does not optimize for a stale threat model.

A 30-day follow-through check

Revisit the issue after the emergency response window. Confirm that temporary containment has either been removed safely or converted into a supported permanent control; that every affected asset has a recorded owner and final disposition; that credential or identity changes reached dependent systems; and that detection logic still produces useful telemetry. Capture any missed inventory, unclear ownership, failed rollback, logging gap or dependency discovered during the event as a concrete improvement item. The goal is to leave the organization with a smaller attack surface and a faster future response, not merely a closed advisory.

Keep a defensible decision record

For BREEZE COMET readiness, document which systems can initiate or sign transactions, which roles can change beneficiaries or payment routing, what independent approvals exist, how quickly suspicious payments can be stopped, and which endpoint, identity and payment records must be retained for a joint cyber-fraud investigation. Capture who approved the final risk disposition and the date the temporary incident controls can be removed or must be reviewed again. A concise decision record prevents emergency actions from becoming undocumented permanent architecture and gives the next responder a verified starting point instead of forcing the team to reconstruct the event from tickets and memory.

References

Continue in the Cybersecurity pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

Coverage intelligence

Published
Coverage pillar
Cybersecurity
Source credibility
40/100 — low confidence
Topics
BREEZE COMET · Financial cybercrime · Brazil · Payment security · Threat intelligence
Sources cited
2 sources (cloud.google.com, thehackernews.com)
Reading time
6 min

References

  1. Financially Motivated Threat Actor BREEZE COMET Targets Brazil — Google Threat Intelligence Group
  2. Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — The Hacker News
  • BREEZE COMET
  • Financial cybercrime
  • Brazil
  • Payment security
  • Threat intelligence
Back to curated briefings

Source feedback

Editorial

Found a factual issue, superseded source, broken citation, or important context we should review? Send the specific claim and supporting source through the correction path so it can be evaluated against the article record.