BREEZE COMET: The AI-Assisted Crew That Broke Into Brazil’s Banks, And Why U.S. Businesses Should Pay Attention

BREEZE COMET hackers breach Brazilian banks with AI-written scripts, cybersecurity lesson for U.S. businesses

A financially motivated hacking group tracked as BREEZE COMET has been sitting inside Brazilian banks since 2024. Google’s Threat Intelligence Group and Mandiant just laid out how they did it, and one detail stands out from the rest: parts of their toolkit were written with generative AI.

This isn’t a story about a faraway bank losing money. It’s a preview of what mid-sized companies in the U.S. are going to face next.

What Actually Happened

BREEZE COMET (previously tracked as UNC5669) targeted Brazilian financial institutions and got into the systems that move money, Pix, STR, and Boleto. Once inside, they pushed hundreds of fraudulent transactions in 24 to 48 hours, then cleared the logs behind them. At least one confirmed heist ran into the tens of thousands of dollars, and researchers believe more are hidden in the wash of everyday transactions.

They got in the boring way. Password spraying. Vishing calls where someone pretended to be IT support and talked an employee into installing AnyDesk. Attempts to recruit insiders. In one case, they physically plugged rogue hardware into a retail store network.

None of that is exotic. It works on U.S. businesses every week.

The AI Part, In Plain English

Mandiant found that a chunk of BREEZE COMET’s scripts were clearly written by a large language model. They were functional but had the tells: verbose comments, unrolled loops, tidy headers, no human shortcuts.

Why does that matter to you?

Because it means the time between “we want a custom tool for this target” and “we have a working custom tool” just got shorter. A group that used to need a skilled developer for every new script can now generate one over lunch. The cost of running a targeted, patient, multi-stage attack keeps dropping.

How the Attack Chain Worked

Once inside, BREEZE COMET layered multiple backdoors written in different languages, Java, Nim, Go, Rust, so removing one didn’t kick them out. They tunneled traffic through DNS and fake HTTPS servers on port 443 to blend in with normal web activity. Then they searched compromised machines for banking certificates and mTLS credentials using very specific keywords (boleto, cnab, remessa, webhook.pix) to find the exact keys they needed to move money.

The pattern is what matters more than the tool names: quiet entry, redundant persistence, targeted search for the credentials that unlock the real prize, then a fast burst of fraud before anyone reconciles the books.

Why This Isn’t Just a Brazil Problem

GTIG says the same staging infrastructure has already been reused on government sites in Nigeria, Paraguay, Ghana, and Venezuela. Groups that succeed with a playbook expand it. And other actors copy what works.

The template BREEZE COMET is proving out, AI-assisted tooling plus old-school social engineering plus direct attacks on payment plumbing, is going to show up in North America. Community banks, credit unions, payment processors, title companies, and any business that moves large wires are the natural next targets.

What Businesses Should Do This Quarter

  1. Treat IT support calls the same way you treat wire transfer requests. Out-of-band verification, on a known number, before anyone installs anything. This is the single move that would have stopped BREEZE COMET at several victims.
  2. Get phishing-resistant MFA on email, remote access, and admin accounts. Text codes aren’t enough. See our note on passwordless authentication.
  3. Audit which remote access tools are installed across your fleet. AnyDesk, ScreenConnect, TeamViewer, and their cousins are the exact tools attackers want you to have. If you don’t use it, remove it. If you do, restrict it. Related reading: ScreenConnect CVE-2026-3564.
  4. Watch outbound traffic, not just inbound. BREEZE COMET’s backdoors phoned home through DNS and fake HTTPS. Deep packet inspection on egress catches what a firewall alone misses.
  5. Put application control on user-writable folders. A lot of this campaign ran out of directories a normal employee can write to. Blocking execution there kills the loaders.
  6. Rotate the keys and certificates your finance systems actually rely on, and know where they live. The attackers knew. Do you?

The Bottom Line

BREEZE COMET didn’t win with a genius zero-day. They won with patient social engineering, cheap AI-generated scripts, and a very clear read of where the money moves. That combination is going to keep getting cheaper.

If you’re a bank, a wealth advisor, a title company, or any business that pushes money for clients, the question isn’t whether this style of attack reaches you. It’s whether the basics, MFA, monitoring, remote access hygiene, incident response planning, are in place before it does.

If you’re not sure, we can look. Level5 Management runs a no-obligation security assessment for South Florida businesses (and clients across Colorado and Arizona). You get a written list of what’s exposed and what to fix first. If you already have an IT provider, use the report to pressure-test them. That’s fine with us.

Article written by the Level5 Management team. Level5 Management is a Boca Raton–based managed IT, cybersecurity, and compliance partner serving law firms, CPAs, wealth advisors, property managers, medical practices, and nonprofits across South Florida since 2008.

Secret Link