← BACK TO FEED
TAG

financial fraud1 article

Two Criminal Groups Are Quietly Gutting Brazil's Financial Infrastructure

A newly identified threat actor called **Slim Spider** has been conducting sophisticated attacks on Brazilian financial institutions since at least March 2026, targeting cryptocurrency assets and instant payment accounts linked to Brazil's Pix system. The group demonstrates advanced cloud security knowledge, using custom scripts to steal cloud credentials, enumerate secrets, and derive Ethereum wallet addresses, while deploying backdoors and malicious pipelines to maintain access and evade detection. Separately, another cybercrime group called **Breeze Comet** has been infiltrating Brazilian financial systems since 2024 to execute fraudulent transactions via Pix and other payment infrastructure, with both groups highlighting a broader shift from retail banking fraud toward direct attacks on core financial infrastructure.

9 Sept 2026