
TL;DR
Mandiant's investigation into Brazilian financial services revealed that the threat actor BREEZE COMET is manipulating payment systems for fraudulent transfers. This group, also known as UNC5669, poses significant risks to the eCommerce sector in Brazil.
✦ Why It Matters
Strengthen your payment system security protocols to protect against BREEZE COMET's fraudulent activities.
Key Takeaways
How It Works
BREEZE COMET uses a combination of compromised websites and custom malware to gain initial access to financial networks. They employ tools like COBALTSPIN for lateral movement and maintain persistence through backdoors like LIGHTPAINT and MILDFROST.
By leveraging generative AI, they automate the creation of reconnaissance scripts and streamline their attack processes, allowing for rapid execution of fraudulent transactions.
Related