A financially motivated group called Breeze Comet targeted Brazilian financial and retail organizations by impersonating IT support and convincing staff to install remote-access tools. After gaining access, the attackers moved into internal payment systems (like Pix/STR/Boleto) and executed hundreds of fraudulent transactions while attempting to erase evidence.
How the Attack Worked
A financially motivated group known as Breeze Comet targeted Brazilian financial and retail organizations by combining password spraying with social engineering. In many cases, attackers placed voice calls impersonating internal IT support teams and persuaded employees to install remote monitoring and management (RMM) tools such as AnyDesk. Once access was granted, the attackers moved into internal systems tied to Brazilian payment rails, including Pix, STR, and Boleto, and executed hundreds of fraudulent transactions.
A separate documented case relied on WhatsApp instead of phone calls. There, attackers posed as IT support staff in a chat conversation and guided a victim to run a PowerShell script, framed as part of a routine corporate application update. That script served as a reconnaissance tool, giving the attackers visibility into the victim's environment before further action.
Why It Succeeded
The pretexts worked because they mimicked normal IT support interactions that employees are conditioned to trust. A phone call or chat message claiming to be from internal IT, requesting a quick tool install or script run to fix or update something, does not automatically look suspicious to a busy employee. The attackers also used compromised but legitimate-seeming websites to stage their tools and public notepad sites like dontpad.com to move stolen data, which helps malicious traffic blend in with ordinary web activity and reduces the chance of raising alarms.
What to Watch For
- Unsolicited calls or messages claiming to be from IT support, especially ones requesting installation of remote access software like AnyDesk
- Requests to run PowerShell scripts manually, outside of any formal deployment or update process
- IT support outreach delivered through informal channels such as WhatsApp rather than official ticketing or helpdesk systems
- Pressure to act quickly on a supposed system update or fix without a corresponding ticket or change request reference
- Unusual destinations for data transfer, including public notepad-style websites
Building Resistance
Organizations in finance, payments, and retail should train staff, particularly those in finance, treasury operations, and roles that interact with IT helpdesks, to treat unsolicited IT support outreach with skepticism. Any request to install remote-access software or run a script should be verified through an official channel before action is taken, regardless of how urgent or routine it sounds. Establishing a clear, well-known process for legitimate software updates, one that never involves ad hoc scripts delivered over chat or phone, gives employees a concrete standard to compare against when a real request arrives. Encouraging staff to report unusual links or data destinations, rather than assume they are benign because they appear on a familiar-looking site, can also help surface this kind of activity earlier.
Key findings
- Initial access included password spraying plus voice calls impersonating IT support to convince victims to install remote tools (e.g., AnyDesk).
- A documented case used WhatsApp messages to pose as IT support and guide a victim to run a PowerShell script under the pretext of updating a corporate application.
- The group focused on organizations connected to Brazilian payment rails (Pix, STR, Boleto) and used compromised accounts and tooling to execute hundreds of fraudulent transactions.
- Attackers used trusted-but-compromised websites and public notepad sites (dontpad[.]com) to host tools or exfiltrate data to reduce detection.
Who’s being targeted
- Commonly targeted roles: Finance, Payments/Treasury Operations, IT Service Desk, Retail store operations, Security awareness training for all employees (with emphasis on remote support requests).
- Affected industries: Financial services, Retail, E-commerce, Banks, Payment processors, Fintech, Exchanges, Banking software providers.
- Attack channels: vishing, whatsapp.
- Impersonated: Internal IT support team, IT support personnel.
Red flags to watch for
- Unsolicited IT support outreach asking to install remote access software
- Pressure to install tools outside normal software deployment processes
- No ticket/change request reference provided before requesting access
- IT support contacting via WhatsApp for software updates
- Request to run PowerShell scripts manually
- Update instructions not delivered through official IT channels/MDM or the corporate software portal
Frequently asked questions
How did attackers gain initial access in this campaign?
Initial access combined password spraying with voice calls impersonating IT support teams that convinced targets to install remote monitoring tools such as AnyDesk.
What role did WhatsApp play in the attack?
In one documented case, attackers posed as IT support over WhatsApp and guided a victim to install a PowerShell reconnaissance script under the pretext of a corporate application update.
Which industries were targeted?
The group focused on organizations connected to Brazilian payment rails including financial services, retail, banks, payment processors, and fintech companies.
How did the attackers avoid detection?
They used compromised but trusted websites to stage tools and exfiltrated data to public notepad sites like dontpad.com, which helped blend malicious traffic with legitimate activity.
Read the video transcript
In Brazil, fake IT support is being used to drain Pix, STR, and Boleto accounts inside real companies. Breeze Comet calls you, says they're IT, and pushes you to install AnyDesk, or WhatsApps you a 'PowerShell update' for a corporate app. Once you run it, they jump into our payment systems and fire off hundreds of Pix transfers. Real IT does not cold-call you on WhatsApp to run PowerShell, and they don’t ask you to install AnyDesk without a ticket or change request. They also won’t send tools from random links like compromised sites or dontpad.com. If anyone claiming to be IT asks you to install AnyDesk or run a script, stop and verify through our official IT channel or ticketing system before you do anything.