Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064 . In this blog, we detail BREEZE COMET’s tactics and toolkit, and provide mitigation recommendations and det
Exploiteerbaarheid: geen exploit bekend. Blootstelling: niet internet-facing / geen bekende blootstelling. Gemeentelijke relevantie: geen match met de gemeentelijke context. Impact: alleen technische impact. Bronvertrouwen: middel.
Scorecomponenten
geen exploit bekend
niet internet-facing / geen bekende blootstelling
geen match met de gemeentelijke context
alleen technische impact
beperkt bevestigd
workaround beschikbaar
Geen automatische bestuurlijke escalatie — operationeel op te volgen.
Prioriteit: monitoren
Aanbevolen reactietijd: monitoren
Monitoren (45/100) — monitoren. Bepalend: gemeentelijke relevantie (100/100) en handelingsurgentie (45/100). Houd dit in de gaten; directe actie is nu niet nodig. Deze prioritering is regelgebaseerd en navolgbaar; weeg de aannames en onzekerheden mee voor de eigen gemeentelijke omgeving.
laag — De technische ernst is beperkt.
laag — Er zijn geen concrete aanwijzingen voor misbruik.
zeer hoog — Dit raakt technologie of processen die bij vrijwel elke Nederlandse gemeente in gebruik zijn.
midden — Plan beoordeling en opvolging in; directe actie is nu niet vereist.
Positieve factoren
De dreiging raakt identity-, Microsoft 365- of Entra-technologie die vrijwel elke gemeente gebruikt.
Bron: Technologieherkenning in titel, samenvatting en labels
De dreiging raakt remote access of VPN (zoals Citrix, Fortinet, Ivanti of Palo Alto): vaak direct vanaf internet bereikbaar.
Bron: Technologieherkenning in titel, samenvatting en labels
De dreiging raakt een leverancier of de toeleveringsketen; gemeenten zijn sterk afhankelijk van externe leveranciers.
Bron: Technologieherkenning in titel, samenvatting en labels
Remote access en VPN zijn direct vanaf internet bereikbaar en een geliefd doelwit; dit verhoogt de urgentie.
Bron: Technologieherkenning in titel, samenvatting en labels
Negatieve factoren
De zekerheid is 'likely'; een onbevestigd signaal verlaagt de urgentie tot het is geverifieerd.
Bron: Zekerheidsinschatting van de radar
Aannames
Onzekerheden
Deze prioritering is regelgebaseerd en navolgbaar. Een CISO kan deze onderbouwing gebruiken richting directie of ICT-management; stem de opvolging af op de eigen gemeentelijke omgeving.
13 concrete acties verdeeld over 6 rol(len). Aanbevolen reactietijd: monitoren.
Taken voor CISO
Laat vaststellen of de getroffen component of het proces binnen de gemeente in gebruik is.
Bewijs vereist: Bevestiging in/uit gebruik door ICT-beheer.
Wijs per actie een eigenaar en deadline toe en bewaak dat de acties worden afgerond.
Laat bevestigen dat de patchstatus en mitigerende maatregelen voor de remote-accessvoorziening op orde zijn.
Bewijs vereist: Bevestiging van het beheerteam of de leverancier.
Laat een korte, concrete waarschuwing aan medewerkers uitgaan.
CISO
Laat vaststellen of de getroffen component of het proces binnen de gemeente in gebruik is.
Bewijs vereist: Bevestiging in/uit gebruik door ICT-beheer.
Wijs per actie een eigenaar en deadline toe en bewaak dat de acties worden afgerond.
Laat bevestigen dat de patchstatus en mitigerende maatregelen voor de remote-accessvoorziening op orde zijn.
Bewijs vereist: Bevestiging van het beheerteam of de leverancier.
Laat een korte, concrete waarschuwing aan medewerkers uitgaan.
ISO / patchmanagement
Controleer of een patch of mitigatie beschikbaar is en bepaal de deadline voor opvolging.
Bewijs vereist: Patch- of mitigatieoverzicht met versienummers.
SOC
Let op afwijkende of mislukte aanmeldingen en sessies op VPN of remote access.
Let op verdachte aanmeldingen, tokenmisbruik en wijzigingen in rechten.
Controleer de e-mailbeveiliging en de meldingen van medewerkers op deze campagne.
ICT-beheer
Breng in kaart welke systemen, applicaties of accounts de kwetsbare component bevatten.
Bewijs vereist: Lijst van geraakte systemen uit de CMDB of inventaris.
Beperk waar mogelijk de internettoegang tot de remote-accessvoorziening tot de patch is uitgevoerd.
Controleer MFA, conditional access en rechten op de getroffen identity- of Microsoft 365-omgeving.
Bewijs vereist: Vastgelegde configuratiecontrole.
Functioneel beheer
Controleer of de geraakte applicatie of koppeling extra aandacht nodig heeft.
Proceseigenaar
Beoordeel wat de dreiging betekent voor de continuiteit van het geraakte proces.
De acties zijn regelgebaseerd gegenereerd. Stem ze af op de eigen gemeentelijke omgeving en wijs per actie een eigenaar en deadline toe.
Relevante logbronnen
MITRE ATT&CK — tactieken
MITRE ATT&CK — technieken
Huntingvragen
KQL-huntingqueries (Microsoft Sentinel)
Verdachte mailboxregels
Toont nieuwe of gewijzigde inbox-regels - vaak gebruikt om e-mail te verbergen of door te sturen.
// Nieuwe of gewijzigde mailboxregels
OfficeActivity
| where TimeGenerated > ago(7d)
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| project TimeGenerated, UserId, Operation, ClientIP, OfficeObjectId
| order by TimeGenerated descFalse positives: Medewerkers maken legitiem regels voor opschoning en doorsturen.
Verdachte Entra ID-aanmeldingen
Toont aanmeldingen met een verhoogd risico of een at-risk-status in Microsoft Entra ID.
// Verdachte Entra ID-aanmeldingen (verhoogd risico)
SigninLogs
| where TimeGenerated > ago(7d)
| where RiskLevelDuringSignIn in ("high", "medium")
or RiskState == "atRisk"
| project TimeGenerated, UserPrincipalName, IPAddress, Location,
AppDisplayName, RiskLevelDuringSignIn, ResultType
| order by TimeGenerated descFalse positives: Reizende medewerkers en VPN-uitgangspunten leveren legitiem verhoogd risico op.
Pieken in mislukte aanmeldingen
Toont bronnen met veel mislukte aanmeldingen - mogelijk password spraying of brute force.
// Pieken in mislukte aanmeldingen (mogelijk password spraying)
SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType != 0
| summarize Mislukt = count(), Accounts = dcount(UserPrincipalName)
by IPAddress, bin(TimeGenerated, 1h)
| where Mislukt > 20 or Accounts > 5
| order by Mislukt descFalse positives: Verlopen wachtwoorden en verkeerd geconfigureerde clients leveren legitieme pieken op.
Aanmeldingen vanuit onbekende landen
Toont geslaagde aanmeldingen vanuit landen buiten het verwachte werkgebied.
// Aanmeldingen vanuit onverwachte landen
let bekendeLanden = dynamic(["NL", "BE", "DE"]);
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| where isnotempty(Location) and Location !in (bekendeLanden)
| summarize Aanmeldingen = count() by UserPrincipalName, Location
| order by Aanmeldingen descFalse positives: Vakanties, grensregio's en cloud-egress kunnen onverwachte landen tonen.
Impossible travel-risicodetecties
Toont aanmeldingen die Entra ID Protection markeert als 'impossible travel' of onbekende kenmerken - mogelijk overgenomen sessies.
// Impossible travel-risicodetecties (Entra ID Protection)
AADUserRiskEvents
| where TimeGenerated > ago(7d)
| where RiskEventType in ("impossibleTravel", "unfamiliarFeatures",
"anonymizedIPAddress")
| project TimeGenerated, UserPrincipalName, RiskEventType, RiskLevel,
IpAddress, Location
| order by TimeGenerated descFalse positives: VPN's, mobiele netwerken en cloud-egress kunnen een legitieme aanmelding als onmogelijke reis laten ogen.
Indicators of compromise
| Type | Waarde | Betrouwbaarheid | TLP |
|---|---|---|---|
| Bestandshash | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec | Middel | TLP:CLEAR |
| Bestandshash | 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a | Middel | TLP:CLEAR |
| Bestandshash | c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a | Middel | TLP:CLEAR |
| Bestandshash | 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb | Middel | TLP:CLEAR |
| Bestandshash | f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f | Middel | TLP:CLEAR |
| Bestandshash | 51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6 | Middel | TLP:CLEAR |
| Bestandshash | d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66 | Middel | TLP:CLEAR |
| Bestandshash | 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8 | Middel | TLP:CLEAR |
False-positive-aandachtspunten
Legitieme nieuwsbrieven, marketingmail en interne mailregels kunnen op phishing lijken. Beoordeel afzender, reputatie en context.
Deze informatie is uitsluitend defensief: detectie en hunting. De KQL-queries zijn read-only en bedoeld voor Microsoft Sentinel.
Vragenlijst
E-mailonderwerp
Uitvraag beveiligingsmelding — reactie gevraagd
E-mailtekst
Geachte heer/mevrouw, Naar aanleiding van een beveiligingsmelding doet onze gemeente een uitvraag bij u als leverancier. Deze uitvraag dient ter verificatie en feitenvaststelling: wij willen vaststellen of en in welke mate de aan onze gemeente geleverde dienstverlening wordt geraakt. Het betreft mogelijk het product of onderdeel "Containers". Wij verzoeken u de onderstaande vragen volledig en onderbouwd te beantwoorden en uw reactie binnen tien (10) werkdagen na ontvangst van dit bericht schriftelijk aan te leveren bij de informatiebeveiligingsfunctie van onze gemeente. Zijn bepaalde gegevens nog niet beschikbaar, dan ontvangen wij graag een tussentijdse terugkoppeling. Vragen: 1. Gebruikt u de kwetsbare component of het geraakte product? 2. Welke versies zijn bij u in gebruik? 3. Is de kwetsbaarheid van toepassing op de dienstverlening aan onze gemeente? 4. Is de kwetsbaarheid inmiddels gepatcht? 5. Zo ja, op welke datum is de patch doorgevoerd? 6. Zo nee, welke mitigerende maatregelen zijn genomen? 7. Is er actief misbruik van de kwetsbaarheid geconstateerd? 8. Is er logging of forensisch onderzoek uitgevoerd? 9. Is er sprake van een risico op een datalek? 10. Wanneer verwacht u een definitieve oplossing door te voeren? 11. Welke restrisico's blijven na de oplossing bestaan? 12. Welke communicatie mogen wij richting onze interne stakeholders gebruiken? Deze uitvraag is bedoeld om de feiten vast te stellen en gezamenlijk tot een passende opvolging te komen. Wij stellen uw tijdige medewerking op prijs. Met vriendelijke groet, [Naam] Namens de informatiebeveiligingsfunctie Gemeente [Gemeente]
Vul vóór verzending de afzender en gemeentenaam in. De tekst is zakelijk en gericht op feitenvaststelling; pas hem aan op de eigen situatie.
Deze dreiging raakt de onderstaande governance-thema's. Met de aanbevolen bewijsstukken kunt u aantonen dat het signaal is opgevolgd — bruikbaar voor BIO2, NIS2/CBW, ISMS en de ENSIA-verantwoording.
Phishing richt zich op medewerkers; bewustwording is de eerste verdedigingslinie.
Aanbevolen bewijs: Recente bewustwordingsactiviteit of een gerichte waarschuwing.
Gestolen inloggegevens worden afgevangen door sterke toegangsbeveiliging en MFA.
Aanbevolen bewijs: Bevestiging dat MFA en conditional access actief zijn.
E-mail- en identiteitsbeveiliging horen bij de basismaatregelen.
Aanbevolen bewijs: Configuratie van e-mailbeveiliging en detectie.
De dreiging en de opvolging ervan horen thuis in de periodieke rapportage aan het management en de directie.
Aanbevolen bewijs: Vermelding in de CISO- of directierapportage informatiebeveiliging.
De radar legt de beoordeling, prioritering en opvolging navolgbaar vast.
Aanbevolen bewijs: Scoringonderbouwing, actiekaart en statusgeschiedenis uit de radar.
Aantoonbare opvolging draagt bij aan de jaarlijkse ENSIA-verantwoording over de BIO.
Aanbevolen bewijs: Overzicht van opgevolgde dreigingen voor de ENSIA-zelfevaluatie.
Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064 . In this blog, we detail BREEZE COMET’s tactics and toolkit, and provide mitigation recommendations and detections to support organizations in defending against this active and developing threat. BREEZE COMET tactics have evolved over time to leverage a customized malware suite and compromised, trusted websites to facilitate initial access, command and control (C2), and to interact with financial software and payment APIs. BREEZE COMET’s operational infrastructure may also indicate intent to expand their infrastructure footprint to other countries in Latin America and Africa. Additionally, we have evidence that BREEZE COMET is using generative artificial intelligence (AI) to support malware development, which may further increase the scale, speed, and sophistication of their operations in the future. BREEZE COMET Targets Brazilian Financial Technology BREEZE COMET operations target organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto. This typically includes banks, payment processors, retailers, exchanges, as well as fintech and banking software providers. To achieve their objective of conducting fraudulent transfers, BREEZE COMET must maintain: Access to the National Financial System Network (Rede Nacional do Setor Financeiro, RSFN) through an entity with this access. Access to mTLS credentials that allow sending authenticated payloads with transactional orders to Pix, STR (Brazilian Reserves Transfer System), or any transactional listener to be executed with minimal restrictions in the name of an organization with available funds. Persistent access to multiple accounts in targeted organizations’ Active Directory and/or cloud environments. Understanding of an organization’s transfer processing procedures, network controls, fintech integrations and anti-fraud systems. In order to support these requirements, BREEZE COMET evolved to operate in multiple compromised environments at the same time, crafting custom C2 malware to automate activities such as reconnaissance, lateral movement, persistence, and exfiltration. Initial Compromise and Establish Foothold BREEZE COMET has used various methods for initial access. In early compromises, Mandiant observed this threat actor use password spraying as well as voice calls impersonating IT support teams to convince users to install Remote Monitoring and Management (RMM) tools such as AnyDesk. Axur corroborates use of voice phishing, and suggests that the group has also attempted to recruit insiders at targeted organizations. In mid-2025, GTIG observed BREEZE COMET using compromised Brazilian small government websites to stage RMM tools, infostealers disguised as legitimate tax or receipt documents (e.g., ComprovantePDF.exe ) , or backdoors such as XWORM set to persist via automated startup shortcut modifications. XWORM is a backdoor that is widely available for purchase on cyber crime forums, with leaked or “cracked” versions also available. BREEZE COMET then used these compromised government websites to facilitate social engineering operations for initial access, and as C2 endpoints. The use of compromised, trusted infrastructure allowed the threat actors to avoid detection by network domain reputation filters. GTIG also observed BREEZE COMET replicating this behavior with municipal domains in Nigeria, Paraguay, Ghana, and Venezuela, suggesting a potentially growing targeting focus. Analysis of compromised municipal domains indicated that BREEZE COMET reused the same staging infrastructure to host and deliver XWORM payloads across operations targeting multiple organizations. In 2025, we first observed BREEZE COMET connect rogue hardware devices directly into retail store networks to establish footholds into targeted environments. From this initial network access, BREEZE COMET moved laterally to internal systems then downloaded the Netcat utility alongside custom scripts to pull down subsequent post-exploitation frameworks from external open directories. Trend Micro has reported that the group also exploited vulnerabilities in JBoss AS servers to gain initial access. Escalate Privileges & Internal Reconnaissance BREEZE COMET used publicly available reconnaissance utilities such as Impacket, ADRecon and ADVipscan, as well as with custom malware, often profiting from environments with low observability. These utilities were often observed being downloaded from GitHub repositories and executed in memory via PowerShell for defense evasion. The threat actor deployed the custom LDAP brute-forcing utility REALBREEZE . Beyond traditional Active Directory compromise, BREEZE COMET specifically targets development and cloud environments to escalate privileges. The group actively mines continuous integration and continuous delivery (CI/CD) environments to steal hard-coded pipeline credentials, application programming interface (API) keys, and highly privileged cloud access tokens. BREEZE COMET used custom scripts to search internal host files and environmental variables to identify mTLS credentials and administrative certificates necessary to authenticate against core banking systems. Observed search terms included: boleto , cnab , remessa , webhook.*pix and instant.*payment . Move Laterally BREEZE COMET abuses standard protocols to navigate the network, using hijacked service accounts to initiate unauthorized Remote Desktop Protocol (RDP) sessions and execute commands via SMB network file shares. BREEZE COMET was observed executing network scanning tools across internal subnets specifically to enumerate available SMB pathways. To maneuver through segmented financial networks and bypass strict internal firewalls, BREEZE COMET deploys specialized routing malware: COBALTSPIN . Written in Rust, COBALTSPIN operates as a lightweight, evasive network tunneler, used to communicate with and maintain persistent network access to financial API infrastructure. By establishing a reverse SOCKS5 proxy over a WebSocket connection, COBALTSPIN routes network traffic securely back and forth between the C2 and internal targets, enabling lateral movement directly through boundary firewalls without requiring built-in persistence mechanisms that might trigger detection. Maintain Presence: Orchestrating the Compromise via Bespoke C2 Frameworks In 2024, BREEZE COMET relied on commercial RMM tools to maintain access to targeted environments. In 2025, BREEZE COMET also deployed malicious Kubernetes pods to maintain persistence and steal cloud secrets, exfiltrating them to public facing notepad websites (such as dontpad[.]com ). In 2025 and 2026 Mandiant identified multiple backdoors that BREEZE COMET developed to establish redundant access and expand their foothold in targeted environments. LIGHTPAINT : This custom Java-based backdoor is specifically designed to install a legitimate VPN, such as SoftEther, and configure it for automated persistence. To protect this access, GTIG observed BREEZE COMET programmatically adding inbound Windows Defender Firewall rules to allow all traffic from the deployed VPN manager, while subsequently clearing the Windows Networking Vpn Plugin Platform event logs to erase forensic evidence of the connection. MILDFROST : Operating as a passive Java JAR backdoor hiding inside the JVM process space, MILDFROST uses classes like DnsCommandBeacon.class to establish slow, covert DNS tunnels. It also serves as a fallback C2; it dynamically queries delegated subdomains to receive instructions and pull down fresh copies of the C++ executables. KICKPLATE : To continuously deliver auxiliary payloads and enforce host-level persistence, BREEZE COMET uses KICKPLATE. This custom Nim-based backdoor impersonates Windows Update Health Tools. It executes commands to control SOCKS5 tunnelers, update registry startup keys, and silently modify Windows services. The group supplements KICKPLATE by abusing native scheduled tasks ( schtasks.exe running as SYSTEM) and malicious shortcut (.lnk) modifications in user startup folders. BOATBEAM : Adding a final layer to their redundant architecture, BREEZE COMET deploys BOATBEAM, a Golang backdoor that initiates a fake IIS HTTPS server on port 443. This artifact hides backdoor traffic by masquerading as a legitimate web server, only activating its C2 functionalities when it receives a specific session cookie. To ensure these persistence mechanisms survive, BREEZE COMET actively impairs endpoint defenses. Telemetry confirms the threat actors executing direct PowerShell commands ( Set-MpPreference -DisableRealtimeMonitoring $true ) to disable Windows Defender's real-time monitoring across compromised hosts, guaranteeing their malware suite remains operational. Furthermore, Mandiant identified evidence that BREEZE COMET used large language models (LLMs) to accelerate the creation of custom scripts for network reconnaissance, credential validation, mass deployment, victim-specific pivoting, and data extraction. Analysis of recovered BREEZE COMET scripts has shown the tools are highly customized and functional, but lack human idiosyncrasies, heavily relying on unrolled code structures, verbose explanatory comments, and standardized execution headers. #!/bin/bash # RODA DENTRO DO 10.0.9.9 - DIRETO NA REDE INTERNA echo "###############################################" echo "### STEP 1: ENUM ALL LINUX (SSH PORT 22) ###" echo "###############################################" # Scan SSH em todos os ranges conhecidos echo "=== SCANNING SSH PORTS ===" > /tmp/ssh_open.txt Figure 1: Excerpt of script showing verbose comments Complete Mission: Mass Fraudulent Transactions Forensic evidence analyzed by Mandiant demonstrates that BREEZE COMET used COBALTSPIN and compromised privileged accounts to access core financial applications. Within 24-48 hours of establishing this access, the threat actor executed two waves of hundreds of fraudulent transactions, based on reporting by a client and third party forensic analysis. Subsequently, BREEZE COMET cleared event logs across compromised hosts to hide evidence of their lateral movement, privilege escalation, and interactions with APIs associated with financial software and payment systems. The attacker also deleted directories they had created during the compromise. Outlook and Implications Since 2024, BREEZE COMET has steadily increased the complexity and effectiveness of their operations manipulating Brazilian financial systems and software, and has successfully executed at least one heist of tens of thousands of USD in assets. This analysis is intended to support financial services, fintech, retail, and government organizations, particularly in Brazil, to track and defend against BREEZE COMET. While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, BREEZE COMET’s campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region.This transition from opportunistic retail banking fraud to direct intrusions into the core financial switch and instant payment infrastructure is notable not just for this shift in targeting, but also the capabilities of the threat actor. BREEZE COMET exemplifies how threat actors are operationalizing generative AI to enhance the speed, scale, and sophistication of their campaigns. By leveraging LLMs to generate bespoke reconnaissance scripts, validate credentials, and automate deployment workflows on the fly, the actor compresses the development lifecycle. This automation also lowers the operational threshold required to coordinate synchronized, multi-environment attacks. Finally, orchestrating their usage of AI-generated tooling alongside bespoke multi-language C2 architectures demonstrates how actors can elevate their overall capabilities and lower technical barriers to entry. The progression to a multi-tiered ecosystem—combining custom-built Rust, Nim, and Go backdoors with AI-accelerated operational scripts—demonstrates a measurable maturation in BREEZE COMET's technical capability. As threat groups increasingly leverage LLMs to streamline routine tradecraft, defenders must anticipate shorter adversary turnaround times and heightened pressure on interconnected financial ecosystems. Remediation and Hardening Application Control & Unapproved Remote Management (RMM) Blocking Enforce Application Control (e.g. Windows WDAC, macOS Gatekeeper/MDM, or Linux fapolicyd) to block execution in user-writable directories (Windows %APPDATA%, macOS ~/Downloads, Linux /tmp or /var/tmp). Partition Linux hosts to mount /tmp and /home with the noexec flag. Audit software inventory to alert on portable RMM execution and unapproved system service/daemon registrations. Train users on social engineering tactics impersonating IT Support. Network Access Control & Branch Physical Hardening Deploy 802.1X Network Access Control (NAC) across physical Ethernet switch ports at branch/retail locations to prevent unauthorized hardware devices from obtaining an internet protocol (IP) address or communicating on internal subnets. Disable unused switch ports and enforce Port Security (e.g. MAC limiting) on critical network drops. Physically restrict access to networking closets and secure public-facing jacks. Active Directory & Credential Hardening Restrict administrative utilities (e.g. ntdsutil.exe, vssadmin.exe) and alert on volume shadow copy creation/deletion. Enforce PowerShell Constrained Language Mode (CLM), Script Block Logging (Event ID 4104), and Antimalware Scan Interface (AMSI) to detect in-memory execution of reconnaissance scripts. Mandate phishing-resistant multifactor authentication (MFA) and lockout controls across all external portals (VPNs, Software-as-a-Service (SaaS)). Deep Packet Inspection & Egress Traffic Control Perform SSL/TLS Decryption and Deep Packet Inspection (DPI) on outbound web traffic rather than relying on domain reputation or .gov top-level domain (TLD) allowlists. Block non-essential egress ports and protocols (e.g., outbound Internet Control Message Protocol (ICMP)) and restrict tunneling utilities like Chisel or GSocket). Segment networks to block lateral SMB (port 445) and RDP (port 3389) traffic between workstations and servers. Kubernetes & Cloud Workload Isolation Enforce strict Kubernetes Role-Based Access Control (RBAC) using least privilege for service accounts. Use dynamic admission controllers (e.g., OPA Gatekeeper or Kyverno) and native Pod Security Admission (PSA) to block privileged containers. Apply egress network policies to block nodes and pods from accessing unauthorized public platforms. Secrets Management & Financial System Micro-Segmentation Mandate a centralized Secrets Manager (e.g., HashiCorp Vault) with access logging; eliminate plaintext keys in code. Implement identity-based / Layer 7 micro-segmentation for financial workloads. Limit administrative access exclusively to dedicated jump hosts via privileged access management (PAM). Indicators of Compromise (IOCs) To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a GTI Collection for registered users. File Indicators Indicator Notes 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec COBALTSPIN 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a REALBREEZE c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a MILDFROST 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb BOATBEAM f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f KICKPLATE 51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6 XWORM d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66 XWORM 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8 XWORM Table 1: File Indicators Network Indicators Indicator Notes dontpad[.]com Paste site used for data exfiltration hxxps://procon[.]go[.]gov[.]br/ComprovantePDF[.]exe Compromised malware Staging Domain hxxps://cmgovernadorluizrocha[.]ma[.]gov[.]br/Comprovantepdf[.]exe Compromised malware Staging Domain hxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/ti[.]zip Compromised malware Staging Domain hxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/notepadd[.]exe Compromised malware Staging Domain hxxp://gcm[.]setelagoas[.]mg[.]gov[.]br/files/tes[.]exe Compromised malware Staging Domain hxxps://minacu[.]go[.]gov[.]br/ComprovantePDF[.]exe Compromised malware Staging Domain hxxps://conseg[.]ssp[.]go[.]gov[.]br/COAF-POLICIAFEDERAL[.]exe Compromised malware Staging Domain hxxps://conseg[.]ssp[.]go[.]gov[.]br/ComprovanteBBpix[.]exe Compromised malware Staging Domain hxxps://suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/attvpn[.]zip Compromised malware Staging Domain hxxps://suporte[.]camaratunapolis[.]sc[.]gov[.]br/ti/1[.]exe Compromised malware Staging Domain hxxps://tisup[.]camaratunapolis[.]sc[.]gov[.]br/SoftEther[.]exe Compromised malware Staging Domain hxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/s[.]zip Compromised malware Staging Domain hxxp://suporte[.]ourinhos[.]sp[.]gov[.]br:443/files/s[.]exe Compromised malware Staging Domain hxxp://suporte[.]ourinhos[.]sp[.]gov[.]br/files/a[.]exe Compromised malware Staging Domain hxxps://servicos[.]salto[.]sp[.]gov[.]br/j[.]jar Compromised malware Staging Domain hxxps://www.mrtb[.]gov[.]ng/apps/attvpn[.]vip Compromised malware Staging Domain hxxp://credeb[.]gov[.]gn/r[.]zip Compromised malware Staging Domain hxxps://sit[.]baer[.]gob[.]ve/r[.]exe Compromised malware Staging Domain hxxps://jmcov[.]gov[.]py/cxv[.]exe Compromised malware Staging Domain Table 2: Network Indicators Detections Google Security Operations (SecOps) Google SecOps customers have access to these broad category rules and more under the "Mandiant Hunting Rules" rule pack. The activity discussed in the blog post is detected in Google SecOps under the rule names: "Network DNS Connections To Pastebin" "Powershell Downloadstring Method With Suspicious Arguments" "Powershell Loading Net Assembly" YARA Rules rule M_Utility_REALBREEZE_2 { meta: author = "Google Threat Intelligence Group" strings: $s1 = "IP/REDE" wide $s2 = "SENHA" wide $s3 = "U\x00S\x00U\x00\xc1\x00R\x00I\x00O\x00:" $s4 = "Arquivo de Texto (*.txt)|*.txt" wide $s5 = "get_SamAccountName" $s6 = "get_txtHostname" condition: uint16(0) == 0x5A4D and all of them } rule G_Tunneler_COBALTSPIN_1 { meta: author = "Google Threat Intelligence Group" strings: $p00_0 = {488985[4]72??4c8b47??4c8b6f??488985[4]eb??4989f04989c5488b85} $p00_1 = {4d8bae[4]4d85ed4c897d??897d??4c8975??89b5[4]74??498bbe[4]4d89ee} condition: uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and ( ($p00_0 in (560000..600000) and $p00_1 in (1500000..1600000)) ) } rule G_Backdoor_BOATBEAM_1 { meta: author = "Google Threat Intelligence Group" strings: $p00_0 = {4d89d84889ce488bbc24[4]e9[4]0f82[4]4c89ac24[4]4c89e74d29ec4c896424} $p00_1 = {e8[4]498903498973??498953??4d8943??488942??488957??4889f8488b4c24} condition: uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and ( ($p00_0 in (1500000..1600000) and $p00_1 in (2700000..2800000)) ) } rule G_Backdoor_MILDFROST_1 { meta: author = "Google Threat Intelligence Group" strings: $s1 = "sc tcp ok" fullword $s2 = "fl comando vazio" fullword $s3 = "noop" fullword $s4 = "wait:" fullword $s5 = "shell:" fullword $s6 = "exec:" fullword $s7 = "upload," fullword $s8 = "dl|" fullword $s9 = "tc|" fullword condition: uint16(0)==0x5a4d and 7 of them }
Categorie 'phishing' op basis van trefwoord 'phishing'. Severity 'low' bepaald op basis van: geen severity-signalen gevonden, standaard 'low'. Confidence 'likely': afgeleid van de betrouwbaarheidsscore van de bron (0.88). Herkende leveranciers/producten: Linux.
Deze dreiging scoort 75/100 voor de gemeentelijke relevantie. Meegewogen: getroffen internetgerichte technologie, veelgebruikte gemeentelijke technologie, impact op identity of Microsoft 365 en een leveranciers- of ketenrisico. Geraakte processen: Microsoft 365 en identity, Netwerk en infrastructuur, Leveranciersketen.
Bestuurlijke duiding
Deze dreiging vraagt om bestuurlijke aandacht. Phishing richt zich op medewerkers en kan leiden tot gecompromitteerde accounts en vervolgschade. Een succesvolle aanval kan de gemeentelijke dienstverlening direct raken en leiden tot uitval, imagoschade of een datalek met meldplicht. Borg dat de portefeuillehouder en de directie geïnformeerd zijn en dat de opvolging belegd en bewaakt wordt.
Geraakte processen
Geraakte technologie
Betrokken rollen
CISO · ISO · SOC · ICT beheer · Leveranciersmanager
Concrete stappen voor ICT-beheer en het securityteam.
Dit zijn algemene handelingsperspectieven. Stem de opvolging af op de eigen omgeving en het ISMS van uw gemeente.
Deel geen vertrouwelijke of persoonsgegevens in dit formulier. Beschrijf je melding algemeen; gevoelige details horen niet op een publieke radar thuis.