
A beforehand undocumented financially motivated menace actor has been linked to assaults focusing on Brazilian monetary establishments since a minimum of March 2026.
Cybersecurity firm CrowdStrike is monitoring the Brazil-based exercise cluster beneath the title Slim Spider.
“The adversary demonstrates deep operational information of Brazilian monetary infrastructure, together with the moment fee service Pix, digital asset platforms, and monetary entities’ cloud environments,” CrowdStrike mentioned.
Slim Spider has been noticed orchestrating a multi-stage intrusion at a Brazil-based monetary establishment in late March 2026, setting its sights on the entity’s cryptocurrency belongings and on the spot fee accounts.
As a part of the assault, the e-crime group is claimed to have developed customized Bash scripts that question the cloud occasion metadata to steal momentary cloud credentials over socket connections.
Upon establishing entry to the group’s cloud setting, the menace actor enumerated all accessible secrets and techniques saved within the cloud credential supervisor and used the “sed” command to clone and modify secret-extracting scripts. The strategy particularly focuses on credentials tied to digital monetary belongings.
“Following exfiltration of digital asset custody secrets and techniques, Slim Spider invoked forged, a element of the Foundry Ethereum developer toolkit, to derive the Ethereum pockets tackle related to a stolen non-public key,” CrowdStrike defined.
“Relatively than counting on third-party libraries that would introduce detection threat, the menace actor carried out cloud-native cryptographic signing instantly by way of OpenSSL inside their Bash scripts. This deliberate selection mirrored refined operational safety consciousness and a nuanced understanding of cloud environments.”
Within the noticed assault, Slim Spider moved to ascertain entry to nodes operating in a cloud container service cluster, whereas deploying backdoors mimicking infrastructure-related binaries to mix with respectable tooling and fly beneath the radar.
The menace actor then pivoted to Azure DevOps, possible utilizing compromised credentials, to run malicious pipelines that deployed further implants throughout a managed Kubernetes cluster. One of many implants was named “spi,” an try to impersonate Sistema de Pagamentos Instantâneos (SPI), which refers back to the central digital infrastructure that processes Pix funds in Brazil.
Slim Spider has additionally been linked to numerous web-based panels to automate and streamline completely different features of the assault chain –
- NEXUS // Scanner, an API endpoint-scanning panel that makes use of Ollama to fit endpoints into 16 classes, equivalent to fintech, banking, fee, and cryptocurrency, and rank them primarily based on availability and authentication choices
- Painel de Emails Entra ID, an e mail reconnaissance panel that searches compromised Microsoft 365 mailboxes sorted into finance, admin, and Brazil classes
- Painel Pix, a transaction panel designed to execute bulk unauthorized Pix transfers from compromised accounts
CrowdStrike mentioned it found an uncovered command-and-control (C2) panel linked to the menace actor that displayed a number of compromised hosts from a number of Brazil-based banks and fintech organizations and certain exfiltrated archive recordsdata.
Based on the cybersecurity vendor’s adversary profile, one other key instrument in Slim Spider’s arsenal is MikeDor, a Go-based backdoor able to harvesting delicate info and monitoring consumer actions.
“Slim Spider’s information of the cloud assault floor permits them to focus on credentials related to a corporation’s precious digital foreign money belongings, together with custody credentials that management cryptocurrency wallets,” it mentioned. “Entry to such belongings can lead to devastating monetary loss for victims.”
“E-crime menace actors are demonstrating more and more refined cloud consciousness, intentionally focusing on the infrastructure and credentials that sit closest to high-value monetary belongings.”
The disclosure coincides with the emergence of one other cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that is infiltrating Brazilian monetary methods to abuse fee infrastructure and perform unlawful transactions for monetary achieve.
Google Risk Intelligence Group (GTIG) and Mandiant mentioned the Portuguese-speaking hacking group breaks into methods that Brazilian monetary organizations use to carry out transactions and initiates funds for itself. The earliest assaults date again to 2024.
The menace actor has additionally been noticed utilizing insufficiently safe Brazilian authorities web sites to stage its malware, and leveraged their repute in follow-on social engineering assaults towards its targets. To make issues worse, Breeze Comet has tried to duplicate this components in different areas, hacking municipal web sites in nations like Nigeria, Paraguay, Ghana, and Venezuela.
The last word purpose is to acquire entry to the monetary purposes that the breached organizations use to make funds, together with Pix, Boleto, and the Reserves Switch System (STR), and execute tons of of fraudulent transactions.
The focusing on of Pix by two completely different menace actors signifies how essentially the most extensively used fee methodology in Brazil has turn out to be a profitable goal throughout working methods.
“Whereas the Latin American cybercrime ecosystem has traditionally been outlined by client-side, high-volume retail fraud, Breeze Comet’s campaigns characterize a notable shift that will function a mannequin for future financially motivated threats towards organizations on this area.”
“This transition from opportunistic retail banking fraud to direct intrusions into the core monetary change and on the spot fee infrastructure is notable not only for this shift in focusing on, but additionally the capabilities of the menace actor.”

