Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

The Hacker News by The Hacker News
September 8, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.

Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.

“The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities’ cloud environments,” CrowdStrike said.

Slim Spider has been observed orchestrating a multi-stage intrusion at a Brazil-based financial institution in late March 2026, setting its sights on the entity’s cryptocurrency assets and instant payment accounts.

As part of the attack, the e-crime group is said to have developed custom Bash scripts that query the cloud instance metadata to steal temporary cloud credentials over socket connections.

Upon establishing access to the organization’s cloud environment, the threat actor enumerated all available secrets stored in the cloud credential manager and used the “sed” command to clone and modify secret-extracting scripts. The approach specifically focuses on credentials tied to digital financial assets.

“Following exfiltration of digital asset custody secrets, Slim Spider invoked cast, a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key,” CrowdStrike explained.

“Rather than relying on third-party libraries that could introduce detection risk, the threat actor implemented cloud-native cryptographic signing directly via OpenSSL within their Bash scripts. This deliberate choice reflected sophisticated operational security awareness and a nuanced understanding of cloud environments.”

In the observed attack, Slim Spider moved to establish access to nodes running in a cloud container service cluster, while deploying backdoors mimicking infrastructure-related binaries to blend with legitimate tooling and fly under the radar.

The threat actor then pivoted to Azure DevOps, likely using compromised credentials, to run malicious pipelines that deployed additional implants across a managed Kubernetes cluster. One of the implants was named “spi,” an attempt to impersonate Sistema de Pagamentos Instantâneos (SPI), which refers to the central digital infrastructure that processes Pix payments in Brazil.

Slim Spider has also been linked to various web-based panels to automate and streamline different aspects of the attack chain –

  • NEXUS // Scanner, an API endpoint-scanning panel that uses Ollama to slot endpoints into 16 categories, such as fintech, banking, payment, and cryptocurrency, and rank them based on availability and authentication options
  • Painel de Emails Entra ID, an email reconnaissance panel that searches compromised Microsoft 365 mailboxes sorted into finance, admin, and Brazil categories
  • Painel Pix, a transaction panel designed to execute bulk unauthorized Pix transfers from compromised accounts

CrowdStrike said it discovered an exposed command-and-control (C2) panel connected to the threat actor that displayed several compromised hosts from several Brazil-based banks and fintech organizations and likely exfiltrated archive files.

According to the cybersecurity vendor’s adversary profile, another key tool in Slim Spider’s arsenal is MikeDor, a Go-based backdoor capable of harvesting sensitive information and monitoring user activities.

“Slim Spider’s knowledge of the cloud attack surface allows them to target credentials associated with an organization’s valuable digital currency assets, including custody credentials that control cryptocurrency wallets,” it said. “Access to such assets can result in devastating financial loss for victims.”

“E-crime threat actors are demonstrating increasingly sophisticated cloud awareness, deliberately targeting the infrastructure and credentials that sit closest to high-value financial assets.”

The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that’s infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.

Google Threat Intelligence Group (GTIG) and Mandiant said the Portuguese-speaking hacking group breaks into systems that Brazilian financial organizations use to perform transactions and initiates payments for itself. The earliest attacks date back to 2024.

The threat actor has also been spotted using insufficiently secure Brazilian government websites to stage its malware, and leveraged their reputation in follow-on social engineering attacks against its targets. To make matters worse, Breeze Comet has attempted to replicate this formula in other regions, hacking municipal websites in countries like Nigeria, Paraguay, Ghana, and Venezuela.

The ultimate goal is to obtain access to the financial applications that the breached organizations use to make payments, including Pix, Boleto, and the Reserves Transfer System (STR), and execute hundreds of fraudulent transactions.

The targeting of Pix by two different threat actors indicates how the most widely used payment method in Brazil has become a lucrative target across operating systems.

“While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, Breeze Comet’s campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region.”

“This transition from opportunistic retail banking fraud to direct intrusions into the core financial switch and instant payment infrastructure is notable not just for this shift in targeting, but also the capabilities of the threat actor.”



Source link

The Hacker News

The Hacker News

Next Post

VMware Price Hike Fears Are ‘Settling Down’ In AI Era For Clients, Partners Say

Recommended.

How AI Could Help Combat Antibiotic Resistance

How AI Could Help Combat Antibiotic Resistance

April 29, 2026
Exposed DeepSeek Database Revealed Chat Prompts and Internal Data

Exposed DeepSeek Database Revealed Chat Prompts and Internal Data

January 29, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

Cloud Market Share Q1 2026: AWS, Microsoft, Google Battling In AI Era

May 4, 2026

Goldman Sachs picks China stocks poised to benefit from a new wave of AI-related hardware exports

August 16, 2026
Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

Anthropic lost control of Claude in latest AI cyber blunder | Computer Weekly

July 31, 2026
Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

Sohu.com to Report Second Quarter 2026 Financial Results on August 10, 2026

July 31, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio