Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
    Cybersecurity

    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    InfoForTechBy InfoForTechSeptember 9, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.

    Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.

    “The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities’ cloud environments,” CrowdStrike said.

    Slim Spider has been observed orchestrating a multi-stage intrusion at a Brazil-based financial institution in late March 2026, setting its sights on the entity’s cryptocurrency assets and instant payment accounts.

    As part of the attack, the e-crime group is said to have developed custom Bash scripts that query the cloud instance metadata to steal temporary cloud credentials over socket connections.

    Upon establishing access to the organization’s cloud environment, the threat actor enumerated all available secrets stored in the cloud credential manager and used the “sed” command to clone and modify secret-extracting scripts. The approach specifically focuses on credentials tied to digital financial assets.

    “Following exfiltration of digital asset custody secrets, Slim Spider invoked cast, a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key,” CrowdStrike explained.

    “Rather than relying on third-party libraries that could introduce detection risk, the threat actor implemented cloud-native cryptographic signing directly via OpenSSL within their Bash scripts. This deliberate choice reflected sophisticated operational security awareness and a nuanced understanding of cloud environments.”

    In the observed attack, Slim Spider moved to establish access to nodes running in a cloud container service cluster, while deploying backdoors mimicking infrastructure-related binaries to blend with legitimate tooling and fly under the radar.

    The threat actor then pivoted to Azure DevOps, likely using compromised credentials, to run malicious pipelines that deployed additional implants across a managed Kubernetes cluster. One of the implants was named “spi,” an attempt to impersonate Sistema de Pagamentos Instantâneos (SPI), which refers to the central digital infrastructure that processes Pix payments in Brazil.

    Slim Spider has also been linked to various web-based panels to automate and streamline different aspects of the attack chain –

    • NEXUS // Scanner, an API endpoint-scanning panel that uses Ollama to slot endpoints into 16 categories, such as fintech, banking, payment, and cryptocurrency, and rank them based on availability and authentication options
    • Painel de Emails Entra ID, an email reconnaissance panel that searches compromised Microsoft 365 mailboxes sorted into finance, admin, and Brazil categories
    • Painel Pix, a transaction panel designed to execute bulk unauthorized Pix transfers from compromised accounts

    CrowdStrike said it discovered an exposed command-and-control (C2) panel connected to the threat actor that displayed several compromised hosts from several Brazil-based banks and fintech organizations and likely exfiltrated archive files.

    According to the cybersecurity vendor’s adversary profile, another key tool in Slim Spider’s arsenal is MikeDor, a Go-based backdoor capable of harvesting sensitive information and monitoring user activities.

    “Slim Spider’s knowledge of the cloud attack surface allows them to target credentials associated with an organization’s valuable digital currency assets, including custody credentials that control cryptocurrency wallets,” it said. “Access to such assets can result in devastating financial loss for victims.”

    “E-crime threat actors are demonstrating increasingly sophisticated cloud awareness, deliberately targeting the infrastructure and credentials that sit closest to high-value financial assets.”

    The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that’s infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.

    Google Threat Intelligence Group (GTIG) and Mandiant said the Portuguese-speaking hacking group breaks into systems that Brazilian financial organizations use to perform transactions and initiates payments for itself. The earliest attacks date back to 2024.

    The threat actor has also been spotted using insufficiently secure Brazilian government websites to stage its malware, and leveraged their reputation in follow-on social engineering attacks against its targets. To make matters worse, Breeze Comet has attempted to replicate this formula in other regions, hacking municipal websites in countries like Nigeria, Paraguay, Ghana, and Venezuela.

    The ultimate goal is to obtain access to the financial applications that the breached organizations use to make payments, including Pix, Boleto, and the Reserves Transfer System (STR), and execute hundreds of fraudulent transactions.

    The targeting of Pix by two different threat actors indicates how the most widely used payment method in Brazil has become a lucrative target across operating systems.

    “While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, Breeze Comet’s campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region.”

    “This transition from opportunistic retail banking fraud to direct intrusions into the core financial switch and instant payment infrastructure is notable not just for this shift in targeting, but also the capabilities of the threat actor.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026

    JADEPUFFER’s Second Wave Multi-Agent Attacks

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.