Two Criminal Groups Are Quietly Gutting Brazil's Financial Infrastructure
A newly identified threat actor called Slim Spider has been running targeted intrusions against Brazilian financial institutions since at least March 2026, with a sharp focus on cryptocurrency custody credentials and Pix instant payment accounts. CrowdStrike, which named and is tracking the group, says the attackers show an unusually detailed working knowledge of Brazilian financial infrastructure, including cloud environments, digital asset platforms, and the payment rails underpinning the country's dominant instant payment system.
The group's toolkit is worth examining in some detail, because it is not amateur stuff. In a late March 2026 attack on a Brazilian financial institution, Slim Spider deployed custom Bash scripts designed to query cloud instance metadata and pull temporary credentials over socket connections. Once inside the cloud environment, they enumerated secrets stored in the cloud credential manager and used the sed command to clone and modify their own exfiltration scripts. Neat, quiet, and clinically focused on financial assets.
After stealing cryptocurrency custody secrets, the group used cast, a component of the Foundry Ethereum developer toolkit, to derive wallet addresses from stolen private keys. Notably, they avoided third-party libraries entirely, opting instead to implement cryptographic signing directly through OpenSSL within their Bash scripts. The reasoning is fairly obvious once you think about it: fewer dependencies means fewer detection hooks. This is a group that understands operational security, not just the technical mechanics of breaking in.
From there, Slim Spider moved into cloud container infrastructure, dropped backdoors disguised as legitimate system binaries, and pivoted to Azure DevOps to run malicious pipelines deploying implants across a managed Kubernetes cluster. One implant was named 'spi', a deliberate nod to Sistema de Pagamentos Instantâneos, the infrastructure that processes Pix transactions. Subtle.
The group also built out a suite of web panels to automate various phases of their operations. NEXUS Scanner uses Ollama to categorise API endpoints across 16 financial sectors and rank them by exploitability. A separate email reconnaissance panel trawls compromised Microsoft 365 mailboxes sorted by role and geography. And then there is Painel Pix, a transaction panel purpose-built to fire off bulk unauthorised Pix transfers from compromised accounts. This is industrialised financial fraud, not opportunistic smash-and-grab.
CrowdStrike also found an exposed command-and-control panel tied to Slim Spider showing compromised hosts across multiple Brazilian banks and fintechs. The group's Go-based backdoor, MikeDor, rounds out their kit, handling credential harvesting and activity monitoring on infected hosts.
As if one financially sophisticated Brazilian threat group were not enough, Google Threat Intelligence Group and Mandiant have separately documented another crew, Breeze Comet, also known by the identifiers CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064. This Portuguese-speaking group has been active since at least 2024, breaking into the systems that financial organisations use to process transactions and then initiating fraudulent payments directly. Targets include Pix, Boleto, and the Reserves Transfer System.
Breeze Comet has been staging malware on poorly secured Brazilian government websites, then using those same sites' reputations to make social engineering attacks more convincing. They have also attempted to export this playbook internationally, compromising municipal websites in Nigeria, Paraguay, Ghana, and Venezuela.
The fact that two separate criminal operations are independently targeting Pix says something significant about where the risk is concentrating. Brazil's payment infrastructure has become enormously successful, which makes it enormously attractive.
Mandiant's assessment is direct: while Latin American cybercrime has historically revolved around high-volume retail fraud targeting individual customers, Breeze Comet represents a meaningful shift toward direct intrusion into core financial switching infrastructure. That is a different category of threat, both in ambition and in the potential scale of damage. If it works in Brazil, expect others to study the model closely.