A new cybercrime group dubbed Slim Spider has infiltrated Brazilian financial institutions, stealing cryptocurrency custody credentials and exploiting cloud environments with advanced tactics. The attacks expose the vulnerability of Brazil's digital payment infrastructure and signal a shift in Latin American cybercrime.
Brazil's financial sector has been rocked by a wave of cyberattacks that go far beyond petty theft. The group known as Slim Spider has managed to infiltrate the core of major financial institutions, extracting cryptocurrency custody secrets and hijacking instant payment accounts with surgical precision. The real shock: these intrusions are not isolated incidents, but part of a calculated campaign targeting the very infrastructure that underpins Brazil's digital economy.
Obiettivo: le chiavi dei portafogli digitali
Slim Spider's operations are anything but amateur. CrowdStrike's analysis reveals a threat actor with an intimate understanding of Brazil's financial backbone, from the ubiquitous Pix instant payment system to the cloud environments that store the digital keys to millions in crypto assets. In late March 2026, the group executed a multi-stage breach at a prominent Brazilian financial institution, deploying custom Bash scripts to siphon temporary cloud credentials and systematically enumerate secrets stored in cloud credential managers.
Instead of relying on off-the-shelf hacking tools, Slim Spider engineered its own scripts, leveraging OpenSSL for cryptographic signing directly within the cloud. This approach not only minimized detection risk but also demonstrated a level of operational security rarely seen in financially motivated attacks. After exfiltrating digital asset custody secrets, the group used cast, a component of the Foundry Ethereum toolkit, to derive Ethereum wallet addresses from stolen private keys-sidestepping third-party libraries that could trigger alarms.
Infiltrazione nei sistemi cloud e DevOps
Once inside, Slim Spider didn't stop at credential theft. The attackers moved laterally, gaining access to nodes in cloud container clusters and deploying backdoors disguised as legitimate infrastructure binaries. Their next pivot: Azure DevOps, where compromised credentials enabled the launch of malicious pipelines and the spread of implants across managed Kubernetes clusters. One implant, tellingly named "spi," was crafted to mimic the Sistema de Pagamentos Instantâneos (SPI), the digital engine behind Pix transactions.
Automation was central to the operation. Slim Spider leveraged web-based panels like NEXUS // Scanner to categorize and rank API endpoints, Painel de Emails Entra ID to sift through compromised Microsoft 365 mailboxes, and Painel Pix to orchestrate mass unauthorized Pix transfers. CrowdStrike's investigation uncovered an exposed command-and-control panel listing compromised hosts from multiple Brazilian banks and fintechs, along with evidence of exfiltrated archives.
Un ecosistema criminale in evoluzione
Slim Spider is not alone in this new breed of cybercriminals. Breeze Comet-also known as CL-CRI-1163, Plump Spider, and SHADOW-AETHER-064-has been infiltrating Brazilian financial systems since 2024, exploiting payment infrastructure to execute fraudulent transactions. According to Google Threat Intelligence Group and Mandiant, Breeze Comet has even abused insecure Brazilian government websites to stage malware and launch social engineering attacks, with attempts to replicate these tactics in Nigeria, Paraguay, Ghana, and Venezuela.
The focus on Pix by both Slim Spider and Breeze Comet underscores the payment system's status as a prime target. The days of simple retail banking fraud are fading; today's attackers are breaching the core switches and instant payment infrastructure, aiming for the highest-value assets with technical sophistication and regional expertise.
Conseguenze e rischi per il settore finanziario
The implications are severe. CrowdStrike warns that access to digital asset custody credentials can result in catastrophic financial losses for victims. The use of advanced backdoors like MikeDor, a Go-based implant capable of harvesting sensitive data and monitoring user activity, further raises the stakes. As e-crime groups demonstrate increasing mastery of cloud environments, the risk to financial institutions-and by extension, their customers-has never been higher.
These developments echo the pattern seen in other high-profile breaches, such as the reported earlier theft of OpenAI and AWS secrets via Langflow vulnerabilities. The message is clear: attackers are targeting the digital heart of organizations, not just their periphery.
Brazil's financial sector now faces a stark reality. The era of opportunistic, low-level fraud is giving way to targeted, infrastructure-level attacks that threaten the integrity of the entire digital payment ecosystem. Slim Spider's campaign is a wake-up call for banks, fintechs, and regulators: without a radical upgrade in cloud security and operational vigilance, the next breach could be even more devastating-and the attackers are already several moves ahead.