Fake IT Calls Push AnyDesk in Brazil Heists

Threat Intelligence · High sophistication
Last updated September 1, 2026

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government websites to get staff to install remote-access tools and malware.

How the attack worked

BREEZE COMET, a financially motivated group tracked by Mandiant and Google, combined two social engineering paths to gain footholds inside Brazilian organizations. In one path, attackers placed voice calls impersonating IT support teams, pressuring employees to install remote monitoring and management tools such as AnyDesk under the guise of fixing a problem. In the other, the group staged malware and remote access tools on compromised small government websites, disguising infostealers as legitimate tax or receipt documents, including a file named ComprovantePDF.exe.

Once inside, the actor moved toward organizations with access to payment rails, specifically those able to initiate transactions through Pix, STR, and Boleto systems, then executed waves of fraudulent transfers. The group also attempted to cover its tracks by clearing event logs and deleting attacker-created directories.

Why it succeeded

Several factors made this approach effective:

  • The IT support pretext exploited the routine trust employees place in internal help desk contacts, especially when the caller sounds knowledgeable and the request feels urgent.
  • Hosting payloads on compromised government websites gave the malicious files an appearance of legitimacy and let attackers avoid detection by network domain reputation filters that might flag unfamiliar or newly registered domains.
  • Disguising executables as everyday business documents, like tax receipts, reduced suspicion since employees expected a PDF, not a program to run.
  • The attackers specifically sought out roles and systems tied to payment processing, concentrating effort where the payoff was largest.

What to watch for

  • Unexpected inbound calls claiming to be internal IT support, especially ones pushing installation of remote access software.
  • Requests to install a generic remote tool like AnyDesk rather than following the organization's standard support process.
  • Downloadable

Key findings

  • BREEZE COMET used voice calls impersonating IT support to convince users to install remote-management tools (e.g., AnyDesk).
  • The group staged malware and remote tools on compromised small government websites and disguised payloads as tax/receipt documents (example filename: ComprovantePDF.exe).
  • The actor targeted organizations that can initiate Pix/STR/Boleto transactions and executed waves of fraudulent transfers after gaining privileged access.
  • They also attempted to hide activity by clearing event logs and deleting attacker-created directories.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Payment operations, IT support/service desk, Retail operations management, Developers/DevOps (CI/CD and cloud teams).
  • Affected industries: Financial services, Fintech, Retail, eCommerce, Government.
  • Attack channels: vishing, website.
  • Impersonated: IT support team, Brazilian municipal/small government website (trusted domain).

Red flags to watch for

  • Unexpected inbound call claiming to be internal IT support
  • Pressure to install remote access software
  • Use of a generic tool (AnyDesk) rather than the company’s standard support process
  • A “document” that is actually an .exe file (e.g., ComprovantePDF.exe)
  • Downloads hosted on a public website instead of the organization’s normal document workflow
  • Unusual request to run a file to view a receipt/tax document
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did BREEZE COMET trick employees into installing remote access tools?

The group made voice calls impersonating IT support teams and convinced users to install Remote Monitoring and Management tools such as AnyDesk to resolve a fake issue.

What made the fake tax document lure effective?

The attackers disguised infostealers as legitimate tax or receipt documents, such as a file named ComprovantePDF.exe, and hosted them on compromised Brazilian small government websites so the source looked trustworthy.

Why were payment operations staff a particular target?

BREEZE COMET targeted organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto, since those roles could enable fraudulent transfers.

What should employees do if they get an unexpected IT support call?

Treat unsolicited IT support calls as untrusted, hang up, and call IT back using a known company number before installing any software.

Read the video transcript

You get a call: “Hi, this is IT support, we need you to install AnyDesk to fix an issue on your PC.” Sounds routine, right? Groups like BREEZE COMET use fake IT calls plus AnyDesk installs to quietly take over machines, then hit banking systems to push Pix, STR, and Boleto transfers out of your company. They even host fake “tax receipts” like ComprovantePDF.exe on real-looking Brazilian government sites, so the download and the caller both feel legit while they steal access and wipe logs. If anyone calls saying they’re IT and asks you to install AnyDesk or run a ‘receipt’ file, hang up and call our real IT number from the directory before you do anything.

Similar attacks

Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026