BREEZE COMET: Breaching Financial Systems and Executing Fraudulent Transfers Using mTLS Credentials
1. Basic Information Article Title : 'Breeze Comet' Tears Into Brazilian & Global Financial Systems Publisher : Dark Reading Publication Date : 2026-09-03 Source : Dark Reading Related Information Source : Google Threat Intelligence Group research Related Malware, Threat Groups, CVEs, and Products : BREEZE COMET, UNC5669, Plump Spider, SHADOW-AETHER-064, COBALTSPIN, LIGHTPAINT, MILDFROST,…
The BREEZE COMET malware strikes financial systems across Brazil and globally, exploiting multiple entry points to execute fraudulent transfers. This sophisticated threat gains access through various methods, including password spraying, vishing posing as IT support, and connecting unauthorized hardware. Once inside, the attacker utilizes vulnerable JBoss AS instances, custom backdoors, and SOCKS5 tunnels to maintain access.
They search for high-privileged accounts and mTLS credentials within Active Directory, cloud, and CI/CD environments, using these credentials to authenticate payment instructions. Within 24 to 48 hours of entering a financial system, hundreds of unauthorized transactions are executed, often bypassing fraud detection measures. The attacker leverages tools like COBALTSPIN's reverse SOCKS5 tunnel to connect to targets on the financial network, serving as a stepping stone for further exploitation.
Success requires gaining initial access, reaching high-privileged credentials, and connecting to the payment network with mTLS credentials. Failure conditions include restrictions on unauthorized device connections, strict management of remote monitoring and management (RMM) tools, and secure storage of mTLS private keys using Hardware Security Modules (HSMs).
Upon successful compromise, the attacker can execute unauthorized transfers and financial losses, gain unauthorized access to sensitive credentials, and persist through multiple backdoors and tunnels, while evading detection by deleting logs and creating new directories.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.