Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 4, 2026
- Feed role
- C2
- Host form
- 0 IP / 19 hostnames
BREEZE COMET, formerly tracked as UNC5669, is a financially motivated cybercriminal threat actor active since 2024 and assessed to operate from Brazil.
Profile source: Mallory opens in a new tabBREEZE COMET
BREEZE COMET, formerly tracked as UNC5669, is a financially motivated cybercriminal threat actor active since 2024 and assessed to operate from Brazil. Its activity overlaps with clusters publicly tracked as Plump Spider and SHADOW-AETHER-064. The group targets Brazilian banks, payment processors, fintechs, cryptocurrency exchanges, retailers, e-commerce organizations, and banking-software providers that can submit transactions through banking software, financial APIs, and payment systems including Pix, STR, and Boleto. Its objective is fraudulent transfer activity using compromised privileged accounts, payment-system access, and transaction-authentication material.
BREEZE COMET gains initial access through password spraying, voice phishing that impersonates IT support personnel, exploitation of vulnerable JBoss AS servers, deployment of unauthorized hardware on retail networks, and malicious content hosted on compromised public-sector websites. It performs internal reconnaissance, scans internal networks, abuses service accounts, and moves laterally over RDP and SMB. The actor seeks Active Directory, cloud, CI/CD, API, certificate, and mTLS credentials, then uses tunneling and proxy tooling to reach core financial applications across network boundaries.
The group uses custom backdoors including LIGHTPAINT, MILDFROST, KICKPLATE, BOATBEAM, REALBREEZE, and COBALTSPIN, as well as commodity remote-management and post-exploitation tools. It establishes persistence through backdoors, service and startup modifications, and malicious Kubernetes workloads; it also uses DNS tunneling and reverse proxying. BREEZE COMET has disabled endpoint protections, cleared event logs, and deleted artifacts after conducting large volumes of fraudulent transactions. Evidence also indicates use of generative AI to accelerate development of reconnaissance, credential-validation, deployment, routing, and data-extraction scripts.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.