thehackernews.com • 3h
Breeze Comet Exploits PIX Transaction Signing Mechanisms within Brazilian Financial Infrastructure
The financially motivated threat actor Breeze Comet (UNC5669) is conducting highly sophisticated attacks against the Brazilian financial sector, specifically targeting the PIX instant payment system. Unlike traditional fraud involving credential theft or forgery, Breeze Comet utilizes specialized modules to manipulate banking software and the transaction signing processes. By exploiting vulnerabilities in how retail e-commerce payment integrations and banking gateways handle transaction signatures, the actor executes hundreds of unauthorized transfers that appear technically valid. This exploitation poses a systemic risk to the integrity of the PIX infrastructure and the broader Brazilian e-commerce ecosystem.
Links:thehackernews.com, Socdefenders, Cypro, Reddit, Socprime, Pk-sharma, Cloudgroup, Inionline •