Fake IT Support Drives Pix Fraud in Brazil

The Hacker News · High sophistication
Last updated September 2, 2026

A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed hundreds of fraudulent transactions while attempting to erase evidence.

How the Attack Worked

A financially motivated group known as Breeze Comet targeted Brazilian financial and retail organizations by combining password spraying with social engineering. In many cases, attackers placed voice calls impersonating internal IT support teams and persuaded employees to install remote monitoring and management (RMM) tools such as AnyDesk. Once access was granted, the attackers moved into internal systems tied to Brazilian payment rails, including Pix, STR, and Boleto, and executed hundreds of fraudulent transactions.

A separate documented case relied on WhatsApp instead of phone calls. There, attackers posed as IT support staff in a chat conversation and guided a victim to run a PowerShell script, framed as part of a routine corporate application update. That script served as a reconnaissance tool, giving the attackers visibility into the victim's environment before further action.

Why It Succeeded

The pretexts worked because they mimicked normal IT support interactions that employees are conditioned to trust. A phone call or chat message claiming to be from internal IT, requesting a quick tool install or script run to fix or update something, does not automatically look suspicious to a busy employee. The attackers also used compromised but legitimate-seeming websites to stage their tools and public notepad sites like dontpad.com to move stolen data, which helps malicious traffic blend in with ordinary web activity and reduces the chance of raising alarms.

What to Watch For

  • Unsolicited calls or messages claiming to be from IT support, especially ones requesting installation of remote access software like AnyDesk
  • Requests to run PowerShell scripts manually, outside of any formal deployment or update process
  • IT support outreach delivered through informal channels such as WhatsApp rather than official ticketing or helpdesk systems
  • Pressure to act quickly on a supposed system update or fix without a corresponding ticket or change request reference
  • Unusual destinations for data transfer, including public notepad-style websites

Building Resistance

Organizations in finance, payments, and retail should train staff, particularly those in finance, treasury operations, and roles that interact with IT helpdesks, to treat unsolicited IT support outreach with skepticism. Any request to install remote-access software or run a script should be verified through an official channel before action is taken, regardless of how urgent or routine it sounds. Establishing a clear, well-known process for legitimate software updates, one that never involves ad hoc scripts delivered over chat or phone, gives employees a concrete standard to compare against when a real request arrives. Encouraging staff to report unusual links or data destinations, rather than assume they are benign because they appear on a familiar-looking site, can also help surface this kind of activity earlier.

Key findings

  • Initial access included password spraying plus voice calls impersonating IT support to convince victims to install remote tools (e.g., AnyDesk).
  • A documented case used WhatsApp messages to pose as IT support and guide a victim to run a PowerShell script under the pretext of updating a corporate application.
  • The group focused on organizations connected to Brazilian payment rails (Pix, STR, Boleto) and used compromised accounts and tooling to execute hundreds of fraudulent transactions.
  • Attackers used trusted-but-compromised websites and public notepad sites (dontpad[.]com) to host tools or exfiltrate data to reduce detection.

Who’s being targeted

  • Commonly targeted roles: Finance, Payments/Treasury Operations, IT Service Desk, Retail store operations, Security awareness training for all employees (with emphasis on remote support requests).
  • Affected industries: Financial services, Retail, E-commerce, Banks, Payment processors, Fintech, Exchanges, Banking software providers.
  • Attack channels: vishing, whatsapp.
  • Impersonated: Internal IT support team, IT support personnel.

Red flags to watch for

  • Unsolicited IT support outreach asking to install remote access software
  • Pressure to install tools outside normal software deployment processes
  • No ticket/change request reference provided before requesting access
  • IT support contacting via WhatsApp for software updates
  • Request to run PowerShell scripts manually
  • Update instructions not delivered through official IT channels/MDM or the corporate software portal
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers gain initial access in this campaign?

Initial access combined password spraying with voice calls impersonating IT support teams that convinced targets to install remote monitoring tools such as AnyDesk.

What role did WhatsApp play in the attack?

In one documented case, attackers posed as IT support over WhatsApp and guided a victim to install a PowerShell reconnaissance script under the pretext of a corporate application update.

Which industries were targeted?

The group focused on organizations connected to Brazilian payment rails including financial services, retail, banks, payment processors, and fintech companies.

How did the attackers avoid detection?

They used compromised but trusted websites to stage tools and exfiltrated data to public notepad sites like dontpad.com, which helped blend malicious traffic with legitimate activity.

Read the video transcript

In Brazil, fake IT support is being used to drain Pix, STR, and Boleto accounts inside real companies. Breeze Comet calls you, says they're IT, and pushes you to install AnyDesk, or WhatsApps you a 'PowerShell update' for a corporate app. Once you run it, they jump into our payment systems and fire off hundreds of Pix transfers. Real IT does not cold-call you on WhatsApp to run PowerShell, and they don’t ask you to install AnyDesk without a ticket or change request. They also won’t send tools from random links like compromised sites or dontpad.com. If anyone claiming to be IT asks you to install AnyDesk or run a script, stop and verify through our official IT channel or ticketing system before you do anything.

Similar attacks

Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
AI Voice “Apple Support” Phishing + Fake IT Helpdesk

AI Voice “Apple Support” Phishing + Fake IT Helpdesk

This news roundup describes real social-engineering operations where attackers impersonate trusted support teams to trick people into giving up secrets. One campaign uses email/SMS/WhatsApp plus AI voice calls pretending to be Apple Support to steal iPhone passcodes, while another uses phishing…

August 27, 2026
Deepfake Job Interviews and Vishing Hit Enterprises

Deepfake Job Interviews and Vishing Hit Enterprises

CrowdStrike warns that attackers are using AI to make social engineering faster and more convincing, including AI-generated resumes and deepfake job interviews to infiltrate companies. The report also describes vishing campaigns that quickly pivot from stealing accounts to stealing data from SaaS…

August 3, 2026