Wire Observer.
Technology

AI‑Powered Malware Enables BREEZE COMET to Hijack Brazil’s Payment Networks

AI‑Powered Malware Enables BREEZE COMET to Hijack Brazil’s Payment Networks

Brazilian banks and payment processors are confronting a new wave of cyber‑attacks that bypass individual accounts and strike directly at the systems that move money. Security researchers have identified a financially driven group calling itself BREEZE COMET, which leverages artificial‑intelligence‑assisted malware to infiltrate transaction platforms and initiate unauthorized transfers.

The collective, previously catalogued by threat‑intel firms as UNC5669, has shifted its focus from traditional phishing or credential theft to compromising the back‑end infrastructure of financial institutions. By obtaining privileged access within core banking applications, the actors can submit fraudulent payment instructions that appear legitimate to internal controls.

What sets BREEZE COMET apart is its use of AI to streamline the development and deployment of malicious code. Machine‑learning models generate obfuscated payloads, adapt to sandbox detection, and even tailor exploits to the specific software stacks found in Brazilian banks. This automation reduces the time needed to craft a functional attack, allowing the group to launch multiple campaigns in rapid succession.

Initial investigations have linked the malware to several incidents where banks reported unexplained outbound transfers totalling millions of dollars. In response, affected institutions have temporarily halted certain processing channels and are conducting forensic reviews of their networks. The Central Bank of Brazil has issued an advisory urging banks to audit privileged accounts and to implement multi‑factor authentication for any system that can initiate payments.

The emergence of AI‑enhanced threats reflects a broader trend across the region, where criminal groups are adopting sophisticated tools once reserved for state‑level actors. Latin America’s financial sector, long a target due to high transaction volumes and legacy systems, is now grappling with adversaries that can dynamically evade traditional security products.

Cybersecurity experts caution that the challenge lies not only in detecting the malicious code but also in monitoring the legitimate‑looking transaction requests it generates. Recommendations include deploying behavioural analytics that flag anomalous payment patterns, tightening access controls around batch‑processing modules, and conducting regular red‑team exercises that simulate AI‑driven intrusion attempts.

Law‑enforcement agencies, both domestic and international, have opened coordinated investigations into BREEZE COMET’s operations. While attribution remains tentative, the group’s public‑facing communications suggest a profit‑first motive rather than geopolitical intent. Analysts expect that as AI tools become more accessible, similar tactics could spread to other financial ecosystems, prompting regulators worldwide to revisit cyber‑resilience frameworks.

Aarav Mehta — Technology desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related