Close Menu
NCIJ Network NCIJ Network
    What's Hot

    World Cup final scorer Torres leads Ballon d’Or nominees

    September 8, 2026

    British widow faces deportation from Sweden after 22 years

    September 8, 2026

    Public opposed to disability benefit cuts, major survey suggests

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • World Cup final scorer Torres leads Ballon d’Or nominees
    • British widow faces deportation from Sweden after 22 years
    • Public opposed to disability benefit cuts, major survey suggests
    • New law to force tech firms to prevent children from taking nude images
    • OpenAI Just Claimed a Huge Math Discovery. Some Academics Are Crying Foul
    • Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
    • 1,000 Museum Visitors Dive Into NASA Sea Level Science on World Ocean Day
    • US Police Fear Meta Glasses Are Watching Them Back: Report
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.

    Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.

    “The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities’ cloud environments,” CrowdStrike said.

    Slim Spider has been observed orchestrating a multi-stage intrusion at a Brazil-based financial institution in late March 2026, setting its sights on the entity’s cryptocurrency assets and instant payment accounts.

    As part of the attack, the e-crime group is said to have developed custom Bash scripts that query the cloud instance metadata to steal temporary cloud credentials over socket connections.

    Upon establishing access to the organization’s cloud environment, the threat actor enumerated all available secrets stored in the cloud credential manager and used the “sed” command to clone and modify secret-extracting scripts. The approach specifically focuses on credentials tied to digital financial assets.

    Cybersecurity

    “Following exfiltration of digital asset custody secrets, Slim Spider invoked cast, a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key,” CrowdStrike explained.

    “Rather than relying on third-party libraries that could introduce detection risk, the threat actor implemented cloud-native cryptographic signing directly via OpenSSL within their Bash scripts. This deliberate choice reflected sophisticated operational security awareness and a nuanced understanding of cloud environments.”

    In the observed attack, Slim Spider moved to establish access to nodes running in a cloud container service cluster, while deploying backdoors mimicking infrastructure-related binaries to blend with legitimate tooling and fly under the radar.

    The threat actor then pivoted to Azure DevOps, likely using compromised credentials, to run malicious pipelines that deployed additional implants across a managed Kubernetes cluster. One of the implants was named “spi,” an attempt to impersonate Sistema de Pagamentos Instantâneos (SPI), which refers to the central digital infrastructure that processes Pix payments in Brazil.

    Slim Spider has also been linked to various web-based panels to automate and streamline different aspects of the attack chain –

    • NEXUS // Scanner, an API endpoint-scanning panel that uses Ollama to slot endpoints into 16 categories, such as fintech, banking, payment, and cryptocurrency, and rank them based on availability and authentication options
    • Painel de Emails Entra ID, an email reconnaissance panel that searches compromised Microsoft 365 mailboxes sorted into finance, admin, and Brazil categories
    • Painel Pix, a transaction panel designed to execute bulk unauthorized Pix transfers from compromised accounts

    CrowdStrike said it discovered an exposed command-and-control (C2) panel connected to the threat actor that displayed several compromised hosts from several Brazil-based banks and fintech organizations and likely exfiltrated archive files.

    According to the cybersecurity vendor’s adversary profile, another key tool in Slim Spider’s arsenal is MikeDor, a Go-based backdoor capable of harvesting sensitive information and monitoring user activities.

    “Slim Spider’s knowledge of the cloud attack surface allows them to target credentials associated with an organization’s valuable digital currency assets, including custody credentials that control cryptocurrency wallets,” it said. “Access to such assets can result in devastating financial loss for victims.”

    “E-crime threat actors are demonstrating increasingly sophisticated cloud awareness, deliberately targeting the infrastructure and credentials that sit closest to high-value financial assets.”

    The disclosure coincides with the emergence of another cybercrime group dubbed Breeze Comet (aka CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064) that’s infiltrating Brazilian financial systems to abuse payment infrastructure and carry out illegal transactions for financial gain.

    Google Threat Intelligence Group (GTIG) and Mandiant said the Portuguese-speaking hacking group breaks into systems that Brazilian financial organizations use to perform transactions and initiates payments for itself. The earliest attacks date back to 2024.

    Cybersecurity

    The threat actor has also been spotted using insufficiently secure Brazilian government websites to stage its malware, and leveraged their reputation in follow-on social engineering attacks against its targets. To make matters worse, Breeze Comet has attempted to replicate this formula in other regions, hacking municipal websites in countries like Nigeria, Paraguay, Ghana, and Venezuela.

    The ultimate goal is to obtain access to the financial applications that the breached organizations use to make payments, including Pix, Boleto, and the Reserves Transfer System (STR), and execute hundreds of fraudulent transactions.

    The targeting of Pix by two different threat actors indicates how the most widely used payment method in Brazil has become a lucrative target across operating systems.

    “While the Latin American cybercrime ecosystem has historically been defined by client-side, high-volume retail fraud, Breeze Comet’s campaigns represent a notable shift that may serve as a model for future financially motivated threats against organizations in this region.”

    “This transition from opportunistic retail banking fraud to direct intrusions into the core financial switch and instant payment infrastructure is notable not just for this shift in targeting, but also the capabilities of the threat actor.”

    Brazilian Crypto custody Financial institution Secrets Slim spider Steals
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

    SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

    Adobe fixes critical Magento zero-day exploited to backdoor servers

    Hackers build AI frameworks for widescale credential theft

    Why CISOs should focus on real AI threats, not hype

    Mathspace Data Breach Exposes Over 1 Million People

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    World Cup final scorer Torres leads Ballon d’Or nominees

    September 8, 2026

    British widow faces deportation from Sweden after 22 years

    September 8, 2026

    Public opposed to disability benefit cuts, major survey suggests

    September 8, 2026

    New law to force tech firms to prevent children from taking nude images

    September 8, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    World Cup final scorer Torres leads Ballon d’Or nominees

    September 8, 2026

    British widow faces deportation from Sweden after 22 years

    September 8, 2026

    Public opposed to disability benefit cuts, major survey suggests

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.