Breeze Comet Uses Generative AI to Target Financial Infrastructure

Breeze Comet Uses Generative AI to Target Financial Infrastructure

High-reputation municipal and government domains are being hijacked to host malicious tax documents, exploiting the trust users place in official public sector websites to bypass automated filters. This sophisticated method serves as the entry point for the group known as Breeze Comet, a threat actor that has fundamentally altered the landscape of financial cybercrime in Latin America. Previously tracked by researchers as UNC5669, this collective has pivoted away from traditional, high-volume phishing of individual bank customers. Instead, they have adopted a precision-based top-down approach that prioritizes the compromise of core financial infrastructure. By targeting the institutional gateways that manage high-value clearing systems, they effectively circumvent the perimeter defenses of individual institutions. This strategic redirection allows the group to insert themselves directly into the flow of national money transfers, making their fraudulent activities look like legitimate commerce.

Strategic Infiltration: The Shift to Systemic Compromise

The primary objectives of Breeze Comet involve the total subversion of major payment and clearing systems, including high-profile instant payment platforms and national reserve transfer systems. To successfully navigate these highly regulated environments, the attackers must go beyond simple password theft or standard credential harvesting. They focus on acquiring Mutual Transport Layer Security (mTLS) credentials and compromising privileged administrative accounts that hold broad authority over the network. This deep access grants them the oversight necessary to manipulate internal transfer controls and move massive sums of money without triggering immediate security alarms. By operating within the trust boundaries of the financial system itself, the group can mimic the behavior of authorized institutional users, making it exceptionally difficult for traditional fraud detection systems to identify the illicit activity until after the funds have been successfully moved.

Throughout 2026, the scope of these operations has expanded significantly, moving beyond traditional banking into the retail and eCommerce sectors. Security analysts have observed that the infrastructure used by Breeze Comet, including their command-and-control servers, suggests a strategic preparation for broader regional expansion across different continents. There are growing indications that the group is laying the groundwork to export this successful model to other developing financial markets across Latin America and parts of Africa. This expansion is characterized by a high degree of technical adaptability, as the group modifies its tools to suit the specific regulatory and technical requirements of each new target region. The reuse of sophisticated back-ends across diverse targets indicates a highly organized operation with sufficient resources to sustain multiple, concurrent campaigns targeting the very heart of the global financial economy.

Blended Tactics: Digital Exploitation and Physical Breaches

Breeze Comet distinguishes itself through a diverse array of initial access vectors that blend digital exploitation with high-pressure physical intrusion. A cornerstone of their methodology is aggressive voice phishing, or vishing, where operators pose as technical support staff to trick bank employees into installing remote management tools. This social engineering tactic effectively turns internal staff into unwitting accomplices, allowing the attackers to bypass automated security perimeters and establish a persistent foothold within the corporate network. By manipulating the human element of the security chain, they can gain entry to systems that are otherwise shielded by advanced firewalls. These interactions are often highly researched, with attackers using specific internal jargon to increase their credibility and pressure employees into complying with requests that compromise the integrity of the institutional network.

The group further demonstrates its high operational security by hijacking reputable public sector websites to host their malicious payloads. By using compromised municipal and government domains, they exploit the high reputation scores these sites hold in automated filtering systems, making it more likely that employees will trust and download the documents. Most notably, Breeze Comet has been known to use rogue hardware devices, physically connecting unauthorized equipment to internal branch networks. This hybrid approach allows them to circumvent external firewalls entirely, facilitating direct lateral movement within the victim’s infrastructure. Such a tactic requires a level of physical proximity and planning that is rare among cybercriminal groups, suggesting a highly coordinated operational structure that can deploy field agents or recruit local accomplices to perform the physical component of the breach.

AI Integration: Accelerating the Malware Lifecycle

A defining feature of the group’s recent evolution is the integration of generative Artificial Intelligence into their malware development lifecycle. The group utilizes Large Language Models (LLMs) to assist in writing and refining complex scripts for network discovery and credential validation. Rather than replacing human expertise, AI serves as a force multiplier that allows the group to rapidly tailor their malicious tools to the specific technical environment of a victim institution. This automation allows for the creation of unique, polymorphic code that can evade signature-based detection systems. By leveraging these advanced technologies, the group can produce sophisticated scripts that would traditionally take weeks to develop in a matter of hours, ensuring that their tools remain effective even as defensive measures evolve. This marks a significant shift in the technical capabilities of non-state threat actors.

By using AI-assisted automation, the attackers can significantly shorten their dwell time, which is the duration between the initial breach and the final execution of fraud. These scripts can quickly parse intricate directory structures and automate the mass deployment of backdoors across hundreds of systems simultaneously. This increased speed leaves defensive teams with a much narrower window to detect and neutralize the threat, often allowing the group to complete their financial objectives before a response can be coordinated. The ability to automate the discovery of administrative secrets and sensitive tokens means that Breeze Comet can move from the perimeter to the core of a financial network with unprecedented velocity. This rapid progression is a direct result of their investment in AI, which manages the labor-intensive aspects of the attack, leaving the human operators to focus on the high-level execution of the theft.

Technical Superiority: The Modular Rust Toolkit

The group employs a specialized, modular arsenal of malware designed for stealth and persistence, with many tools written in the Rust programming language for enhanced performance and evasion. Their toolkit includes REALBREEZE, a credential-guessing tool for directory services, and COBALTSPIN, which creates stealthy tunnels for attacker traffic by disguising it as standard web communication. Redundant access is maintained through tools like LIGHTPAINT and MILDFROST, which provide fallback communication channels if the primary methods are discovered. Rust’s memory safety and performance characteristics make it an ideal choice for developing malware that must operate undetected on a wide range of hardware. The use of this modern language also makes reverse engineering more difficult for security researchers, as the resulting binaries are often more complex and less predictable than those created with older, more traditional programming languages.

This custom software stack is specifically tuned to hunt for developer secrets, cloud tokens, and API keys. By targeting Continuous Integration and Deployment (CI/CD) pipelines, Breeze Comet attempts to steal the mTLS certificates required to authenticate as a trusted financial entity. Obtaining these certificates is the group’s ultimate goal, as it provides the holy grail of access needed to commit large-scale payment fraud while appearing as a legitimate part of the banking network. This focus on the software supply chain and internal development environments shows a deep understanding of modern enterprise architecture. By compromising the systems that build and deploy financial software, the group can inject their influence into the very foundation of the bank’s digital presence. This level of technical sophistication ensures that their access is not only deep but also resilient against standard password rotations and account lockouts.

Operational Closure: Rapid Fraud and Forensic Sanitization

The final stage of a Breeze Comet operation is characterized by clinical precision and rapid execution. Once they have secured access to core financial applications, the group typically initiates multiple waves of fraudulent transfers within a very short window, often totaling significant sums. In many documented cases, hundreds of individual transfers are completed within a twenty-four to forty-eight hour period, overwhelming the victim’s ability to react in real-time to the unfolding crisis. The speed of these transfers is designed to exploit the lag between transaction processing and fraud review. By the time the institution identifies the pattern of illicit activity, the funds have often been moved through multiple intermediary accounts and converted into assets that are difficult to track or recover. This rapid-fire approach minimizes the window for intervention and maximizes the potential financial gain for the group.

The operations conducted by Breeze Comet throughout 2026 demonstrated a terrifying level of efficiency that traditional security models struggled to contain. Their ability to move from initial access to full-scale financial exfiltration within a forty-eight-hour window rendered many reactive protocols obsolete. To counter such rapid lateral movement, organizations began shifting toward zero-trust architectures that emphasize the protection of mTLS credentials and the rigorous monitoring of CI/CD pipelines. Security teams realized that defending against AI-augmented threats required a proportional investment in automated detection and response capabilities. Moving forward, the industry must prioritize the physical security of network branches alongside digital hardening to prevent rogue hardware intrusions. Enhancing the visibility of internal administrative accounts and implementing immutable logging are no longer optional but essential strategies to withstand these highly targeted infrastructure attacks.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later