Threat actor
BREEZE COMET
Last fetched
BREEZE COMET is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques and also known as 1 other name.
Also known as
UNC5669
Description
BREEZE COMET is a financially motivated threat actor targeting Brazilian financial services, retail, and eCommerce organizations through compromised websites, custom malware, and stolen credentials to manipulate payment systems and execute fraudulent transfers. The group employs custom tools such as REALBREEZE, COBALTSPIN, KICKPLATE, MILDFROST, LIGHTPAINT, and BOATBEAM for reconnaissance, lateral movement, persistence, tunneling, and stealth. Forensic evidence indicates that BREEZE COMET has executed waves of fraudulent transactions within 24-48 hours of compromise, likely stealing tens of thousands of USD in assets. The actor has also leveraged generative AI to enhance malware and script development while expanding its infrastructure across Latin America and Africa.
Techniques by tactic
No ATT&CK techniques are recorded for BREEZE COMET in WhisperGraph.
Attributed infrastructure
Infrastructure with a published ATTRIBUTED_TO link to BREEZE COMET in WhisperGraph. Attribution is sparse graph-wide — this list is rarely exhaustive.
- minacu.go.gov.brHOSTNAME
- procon.go.gov.brHOSTNAME
- conseg.ssp.go.gov.brHOSTNAME
- cmgovernadorluizrocha.ma.gov.brHOSTNAME
- gcm.setelagoas.mg.gov.brHOSTNAME
- www.mrtb.gov.ngHOSTNAME
- jmcov.gov.pyHOSTNAME
References
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from BREEZE COMET into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.