# Breeze Comet targets Brazilian payment infrastructure with custom malware

_Tuesday, September 1, 2026 at 1:19 PM EDT · Security · Latest · Tier 1 — Major_

![Breeze Comet targets Brazilian payment infrastructure with custom malware — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvGVdje0roDTqKcU541FTx34ODDmuBU-qtwYwoW0-qAYscD9yX5stIs8EhQtC7gnwM4WpqNTjYFRRwXm7w97C5tY7eEhCQJ89Y_uesRzrbbuR7knHdEkoDetSlRpfa8XOD_rdChE5yFh3VtBPlChgYRKp9ZDon-0B1_VAM9NOd0_xvgw9gD_YF7lSBXiPI/s1700-nu-rw-lo-l85-e365/brazil.jpg)

Google Threat Intelligence Group and Mandiant say the financially motivated Breeze Comet group has targeted Brazilian financial services, retail, and e-commerce organizations since 2024, manipulating payment systems and banking software to make fraudulent transfers.

The group has completed at least one heist worth tens of thousands of dollars, according to the report. It gains access through password spraying, impersonated IT-support calls, vulnerable JBoss servers, and compromised websites, then uses custom malware and privileged accounts to access payment applications. The activity has culminated in hundreds of fraudulent transactions, the report says.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html)

---
Canonical: https://techandbusiness.org/newswire/HhaFOUY_Lr4z8U-DKGIkyk
Retrieved: 2026-09-02T00:50:59.531Z
Publisher: Tech & Business (techandbusiness.org)
