Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government websites to get staff to install remote-access tools and malware.
How the attack worked
BREEZE COMET, a financially motivated group tracked by Mandiant and Google, combined two social engineering paths to gain footholds inside Brazilian organizations. In one path, attackers placed voice calls impersonating IT support teams, pressuring employees to install remote monitoring and management tools such as AnyDesk under the guise of fixing a problem. In the other, the group staged malware and remote access tools on compromised small government websites, disguising infostealers as legitimate tax or receipt documents, including a file named ComprovantePDF.exe.
Once inside, the actor moved toward organizations with access to payment rails, specifically those able to initiate transactions through Pix, STR, and Boleto systems, then executed waves of fraudulent transfers. The group also attempted to cover its tracks by clearing event logs and deleting attacker-created directories.
Why it succeeded
Several factors made this approach effective:
- The IT support pretext exploited the routine trust employees place in internal help desk contacts, especially when the caller sounds knowledgeable and the request feels urgent.
- Hosting payloads on compromised government websites gave the malicious files an appearance of legitimacy and let attackers avoid detection by network domain reputation filters that might flag unfamiliar or newly registered domains.
- Disguising executables as everyday business documents, like tax receipts, reduced suspicion since employees expected a PDF, not a program to run.
- The attackers specifically sought out roles and systems tied to payment processing, concentrating effort where the payoff was largest.
What to watch for
- Unexpected inbound calls claiming to be internal IT support, especially ones pushing installation of remote access software.
- Requests to install a generic remote tool like AnyDesk rather than following the organization's standard support process.
- Downloadable
Key findings
- BREEZE COMET used voice calls impersonating IT support to convince users to install remote-management tools (e.g., AnyDesk).
- The group staged malware and remote tools on compromised small government websites and disguised payloads as tax/receipt documents (example filename: ComprovantePDF.exe).
- The actor targeted organizations that can initiate Pix/STR/Boleto transactions and executed waves of fraudulent transfers after gaining privileged access.
- They also attempted to hide activity by clearing event logs and deleting attacker-created directories.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Payment operations, IT support/service desk, Retail operations management, Developers/DevOps (CI/CD and cloud teams).
- Affected industries: Financial services, Fintech, Retail, eCommerce, Government.
- Attack channels: vishing, website.
- Impersonated: IT support team, Brazilian municipal/small government website (trusted domain).
Red flags to watch for
- Unexpected inbound call claiming to be internal IT support
- Pressure to install remote access software
- Use of a generic tool (AnyDesk) rather than the company’s standard support process
- A “document” that is actually an .exe file (e.g., ComprovantePDF.exe)
- Downloads hosted on a public website instead of the organization’s normal document workflow
- Unusual request to run a file to view a receipt/tax document
Frequently asked questions
How did BREEZE COMET trick employees into installing remote access tools?
The group made voice calls impersonating IT support teams and convinced users to install Remote Monitoring and Management tools such as AnyDesk to resolve a fake issue.
What made the fake tax document lure effective?
The attackers disguised infostealers as legitimate tax or receipt documents, such as a file named ComprovantePDF.exe, and hosted them on compromised Brazilian small government websites so the source looked trustworthy.
Why were payment operations staff a particular target?
BREEZE COMET targeted organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto, since those roles could enable fraudulent transfers.
What should employees do if they get an unexpected IT support call?
Treat unsolicited IT support calls as untrusted, hang up, and call IT back using a known company number before installing any software.
Read the video transcript
You get a call: “Hi, this is IT support, we need you to install AnyDesk to fix an issue on your PC.” Sounds routine, right? Groups like BREEZE COMET use fake IT calls plus AnyDesk installs to quietly take over machines, then hit banking systems to push Pix, STR, and Boleto transfers out of your company. They even host fake “tax receipts” like ComprovantePDF.exe on real-looking Brazilian government sites, so the download and the caller both feel legit while they steal access and wipe logs. If anyone calls saying they’re IT and asks you to install AnyDesk or run a ‘receipt’ file, hang up and call our real IT number from the directory before you do anything.