BREEZE COMET Financial-System Intrusions
Executive Summary
What happened: Google Threat Intelligence Group and Mandiant reported on 1 September 2026 that the financially motivated actor BREEZE COMET, formerly UNC5669 and overlapping Plump Spider and SHADOW-AETHER-064, has compromised Brazilian financial services, retail, ecommerce, payment, and related environments since 2024. Axur independently documented the actor's IT-support impersonation and a PowerShell reconnaissance payload used against the Pix ecosystem. The objective is access to payment workflows, mTLS credentials, privileged identities, and the infrastructure needed to conduct fraudulent transfers.
How the intrusion works: footholds have included voice-based IT impersonation, coerced RMM installation, compromised government websites staging XWORM and other payloads, exploitation of JBoss AS servers, password spraying, and rogue hardware attached to retail networks. The actor then uses PowerShell and native utilities to inventory hosts, Wi-Fi keys, DNS, domain controllers, cloud and CI/CD secrets, and payment-related files. RDP and SMB support lateral movement. Its redundant custom access stack includes REALBREEZE for LDAP brute forcing; COBALTSPIN, a Rust reverse SOCKS5 proxy over WebSocket; LIGHTPAINT, which installs SoftEther and opens inbound firewall paths; MILDFROST, a Java JAR backdoor using delegated DNS; KICKPLATE, which modifies services and Run keys; and BOATBEAM, which imitates IIS HTTPS on port 443 and activates on a session cookie. Persistence also uses scheduled tasks and startup shortcuts. Observed anti-forensics include disabling Defender real-time monitoring and clearing Windows logs.
Why detection lives in behavior: the eight published hashes provide high-confidence retrospective pivots, but the government-host staging domains are compromised legitimate infrastructure and can be remediated or reused. The more durable Falcon signals are Defender disablement, log clearing, dense PowerShell/network reconnaissance, scripted persistence, and unapproved RMM/VPN execution. DNS from Java is a baseline-driven lead, not proof of MILDFROST. WebSocket SOCKS5 and cookie-gated HTTPS semantics remain a telemetry gap unless process events can be joined to proxy or HTTP evidence.
| Priority | Why now | Coverage delivered | Key limitation |
|---|---|---|---|
| Find defense impairment and anti-forensics, then pivot | Active, developing intrusions target financial workflows | 7 CQL queries: 1 inventory, 4 hunts, 2 alert candidates | Static review only; encrypted tunnel, identity, cloud, Kubernetes, and payment telemetry need tenant-specific validation |
Source and Claim Review
Seven current-run sanitized snapshots preserve three independent research streams and four hardening authorities. S03 is visibly partial and supports only alias/corroboration context.
| ID | Publisher | Tier | Independence group | Accessed | Status |
|---|---|---|---|---|---|
| S01 | Google Threat Intelligence Group / Mandiant | primary-incident-response | google-mandiant | 2026-09-01T11:04:14Z | complete-sanitized |
| S02 | Axur Research Team | primary-research | axur | 2026-09-01T11:04:14Z | complete-sanitized |
| S03 | Trend Micro Research | primary-research | trend-micro | 2026-09-01T11:04:14Z | partial-sanitized |
| S04 | Microsoft Learn | primary-vendor-guidance | microsoft | 2026-09-01T11:04:14Z | complete-sanitized |
| S05 | Microsoft Learn | primary-vendor-guidance | microsoft | 2026-09-01T11:04:14Z | complete-sanitized |
| S06 | CISA | government-guidance | cisa | 2026-09-01T11:04:14Z | complete-sanitized |
| S07 | NIST | government-guidance | nist | 2026-09-01T11:04:14Z | complete-sanitized |
Claim ledger
| Claim | Statement | Sources | Confidence | Contradiction |
|---|---|---|---|---|
| C01 | BREEZE COMET, formerly UNC5669, overlaps activity reported as Plump Spider and SHADOW-AETHER-064. | S01, S02, S03 | high | none |
| C02 | The actor compromises financial services, retail, ecommerce, payment, and related environments to enable fraudulent transfers. | S01, S02 | high | none |
| C03 | Observed initial access includes voice-based IT impersonation and coerced installation of remote-management or reconnaissance tooling. | S01, S02 | high | none |
| C04 | Separate reporting links the activity to compromised web infrastructure and exploitation of JBoss AS servers. | S01, S03 | medium | none |
| C05 | Reconnaissance collected host, user, domain, DNS, network, Wi-Fi credential, and domain-controller data using PowerShell and native utilities. | S01, S02 | high | none |
| C06 | The actor used RDP and SMB with hijacked accounts and deployed network-scanning tools for lateral movement. | S01 | medium | none |
| C07 | COBALTSPIN provides a reverse SOCKS5 proxy over WebSocket for routing traffic through segmented networks. | S01 | medium | none |
| C08 | LIGHTPAINT installs a VPN such as SoftEther, adds inbound firewall rules, and clears related Windows networking logs. | S01 | medium | none |
| C09 | MILDFROST is a Java JAR backdoor that uses delegated DNS subdomains for covert command and control. | S01 | medium | none |
| C10 | KICKPLATE modifies registry startup keys and Windows services and controls SOCKS5 tunnelers. | S01 | medium | none |
| C11 | BOATBEAM exposes an imitation IIS HTTPS service on port 443 and activates C2 behavior on a specific session cookie. | S01 | medium | none |
| C12 | Observed defense evasion includes disabling Windows Defender real-time monitoring and clearing Windows event logs. | S01 | medium | none |
| C13 | The actor searched hosts and environment variables for mTLS certificates, payment-related terms, pipeline credentials, API keys, and cloud tokens. | S01, S02 | medium | none |
| C14 | The actor used scheduled tasks, malicious startup shortcuts, and Windows service modifications for persistence. | S01 | medium | none |
| C15 | Google published eight SHA-256 malware indicators associated with COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, KICKPLATE, and XWORM. | S01 | high | none |
| C16 | Google published compromised government-host infrastructure used for malware staging or command and control. | S01 | high | none |
| C17 | Mandiant observed the actor using AI-assisted scripts for reconnaissance, credential validation, deployment, pivoting, and data extraction. | S01 | medium | none |
Hunt Brief and Attack Chain
The scaffold separates foothold, reconnaissance, movement, C2, persistence, defense evasion, and financial-objective coverage so missing telemetry cannot masquerade as detection.
| Step | Claims | Behavior | Platform | Detection goal |
|---|---|---|---|---|
| 1 | C03, C04 | social engineering, trusted-web staging, server exploitation, or rogue-device foothold | cross-platform | identify user-driven shell/RMM activity and known staging infrastructure |
| 2 | C05, C13 | host, network, domain, credential, CI/CD, and secret reconnaissance | cross-platform | detect dense native-utility and PowerShell reconnaissance |
| 3 | C06 | RDP and SMB lateral movement using hijacked accounts | windows | correlate endpoint execution with tenant authentication/network evidence |
| 4 | C07, C09, C11 | redundant WebSocket, DNS, and HTTPS command-and-control channels | cross-platform | find uncommon process/network pairings and document portable telemetry gaps |
| 5 | C08, C10, C14 | VPN, scheduled-task, startup, registry, and service persistence | windows | find unapproved VPN/RMM and persistence-control changes |
| 6 | C12 | endpoint protection impairment and event-log clearing | windows | detect defender preference changes and anti-forensic commands |
| 7 | C02, C13 | use of stolen credentials and financial workflows for fraudulent transfers | identity/cloud/financial application | hand off to identity, secrets, HSM, and payment-system owners where portable endpoint telemetry ends |
Hypotheses
| ID | Behavior | Telemetry | Use | Lookback | Validation |
|---|---|---|---|---|---|
| H01 | known malware hash presence | ProcessRollup2, PeFileWritten, NewExecutableWritten | hunt | 90d — low-volatility hashes support a longer retrospective window | Use a synthetic non-malicious hash equality check against a controlled test event or known tenant sample; baseline security-lab hosts separately. |
| H02 | PowerShell and native-utility network/domain reconnaissance | ProcessRollup2 | hunt | 30d — covers current activity while bounding command-line scan cost | Run isolated benign commands that emit the targeted argument shapes, then compare against a 30-day help-desk and network-administration baseline. |
| H03 | PowerShell disabling Defender real-time monitoring | ProcessRollup2 | alert-candidate | 30d — defense impairment is high-value and should be retained for incident review | Use an approved isolated lab with a harmless command-line marker that does not change Defender state; baseline authorized security tooling and maintenance accounts. |
| H04 | Windows event-log clearing | ProcessRollup2 | alert-candidate | 30d — anti-forensic behavior should remain visible through incident scoping | Generate an approved inert command-line marker in an isolated test host; baseline legitimate image-build and troubleshooting activity without clearing production logs. |
| H05 | scripted task, service, or Run-key persistence | ProcessRollup2 | hunt | 30d — persistence changes may precede later fraudulent activity | Use nonpersistent dry-run markers in an isolated host and baseline approved deployment-tool parents, signers, accounts, and destinations. |
| H06 | unapproved RMM or VPN execution | ProcessRollup2 | inventory | 30d — supports inventory and incident correlation | Run against a known approved-software inventory and verify that allowlisting by managed path, signer, and owner separates sanctioned deployments. |
| H07 | Java process DNS-tunneling lead | DnsRequest | hunt | 7d — DNS volume aggregation should stay bounded and recent | Confirm DnsRequest process attribution on a known Java workload, then build a seven-day per-application domain and volume baseline before judging outliers. |
| H08 | WebSocket SOCKS5 or cookie-gated HTTPS tunneling | proxy, network sensor, server HTTP logs, or tenant-specific Falcon network telemetry | gap | 14d — current intrusion-scoping window | In an isolated lab, capture known-benign WebSocket and SOCKS5 traffic plus a controlled tunnel; document proxy/EDR field mapping before designing CQL. |
Affected surface and telemetry
The pack assumes broadly available endpoint process telemetry plus DNS events where populated. Network, identity, CI/CD, cloud, Kubernetes, proxy/HTTP, HSM, and payment-system logs are not assumed. Linux process and path variants, IPv6, wrapper lineage, DNS process attribution, and all parser-specific fields require confirmation in the intended repository.
Consolidated IOC Table
| ID | Type | Value | Context | Source | Confidence | Volatility | Action |
|---|---|---|---|---|---|---|---|
| I01 | sha256 | 3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec | COBALTSPIN sample | S01 | high | low | detect |
| I02 | sha256 | 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a | REALBREEZE sample | S01 | high | low | detect |
| I03 | sha256 | c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a | MILDFROST sample | S01 | high | low | detect |
| I04 | sha256 | 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb | BOATBEAM sample | S01 | high | low | detect |
| I05 | sha256 | f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f | KICKPLATE sample | S01 | high | low | detect |
| I06 | sha256 | 51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6 | XWORM sample | S01 | high | low | detect |
| I07 | sha256 | d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66 | XWORM sample | S01 | high | low | detect |
| I08 | sha256 | 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8 | XWORM sample | S01 | high | low | detect |
| I09 | domain | procon.go.gov.br | compromised staging host | S01 | medium | high | enrich |
| I10 | domain | cmgovernadorluizrocha.ma.gov.br | compromised staging host | S01 | medium | high | enrich |
| I11 | domain | gcm.setelagoas.mg.gov.br | compromised staging host | S01 | medium | high | enrich |
| I12 | domain | minacu.go.gov.br | compromised staging host | S01 | medium | high | enrich |
| I13 | domain | conseg.ssp.go.gov.br | compromised staging host | S01 | medium | high | enrich |
| I14 | domain | suporte.camaratunapolis.sc.gov.br | compromised staging host | S01 | medium | high | enrich |
| I15 | domain | tisup.camaratunapolis.sc.gov.br | compromised staging host | S01 | medium | high | enrich |
| I16 | domain | suporte.ourinhos.sp.gov.br | compromised staging host | S01 | medium | high | enrich |
| I17 | domain | servicos.salto.sp.gov.br | compromised staging host | S01 | medium | high | enrich |
| I18 | domain | www.mrtb.gov.ng | compromised staging host | S01 | medium | high | enrich |
| I19 | domain | credeb.gov.gn | compromised staging host | S01 | medium | high | enrich |
| I20 | domain | sit.baer.gob.ve | compromised staging host | S01 | medium | high | enrich |
| I21 | domain | jmcov.gov.py | compromised staging host | S01 | medium | high | enrich |
| I22 | domain | dontpad.com | public paste site used for exfiltration | S01 | medium | high | pivot |
ATT&CK Mapping
Mappings below are analyst inferences from source-backed behavior. IOC correlation and product inventory are intentionally unmapped.
| Tactic | Technique | Name | Behavior | Basis | Sources | Claims |
|---|---|---|---|---|---|---|
| Initial Access | T1566 | Phishing | IT-support impersonation induced users to install attacker-selected tooling | analyst inference | S01, S02 | C03 |
| Discovery | T1016 | System Network Configuration Discovery | scripts collected IP, DNS, adapter, gateway, and domain-controller data | analyst inference | S01, S02 | C05 |
| Lateral Movement | T1021.001 | Remote Services: RDP | hijacked accounts initiated unauthorized RDP sessions | analyst inference | S01 | C06 |
| Lateral Movement | T1021.002 | Remote Services: SMB/Windows Admin Shares | commands were executed through SMB network shares | analyst inference | S01 | C06 |
| Command and Control | T1572 | Protocol Tunneling | COBALTSPIN routes SOCKS5 traffic through WebSocket | analyst inference | S01 | C07 |
| Command and Control | T1071.004 | Application Layer Protocol: DNS | MILDFROST uses DNS tunneling | analyst inference | S01 | C09 |
| Defense Evasion | T1562.001 | Impair Defenses | PowerShell disabled Defender real-time monitoring | analyst inference | S01 | C12 |
| Defense Evasion | T1070.001 | Clear Windows Event Logs | the actor cleared event logs | analyst inference | S01 | C12 |
| Persistence | T1053.005 | Scheduled Task/Job: Scheduled Task | scheduled tasks ran as SYSTEM | analyst inference | S01 | C14 |
| Persistence | T1543.003 | Create or Modify System Process: Windows Service | services were modified for persistence | analyst inference | S01 | C14 |
Native / Non-CQL Hunts
Platform-native review is required where portable endpoint CQL ends.
| Hunt | Log source | Logic | Response |
|---|---|---|---|
| Privileged identity and lateral movement | Windows Security 4624/4625/4672, 4720/4728/4732/4756, 4662, 5136, and RDP/SMB telemetry | Find password-spray-to-success patterns, unexpected privileged-group changes, DCSync-like directory access, and RDP/SMB from unusual sources. | Preserve raw events and session identifiers; correlate to the endpoint timeline before revocation. |
| RMM, VPN, task, service, and Run-key persistence | Windows Service Control Manager 7045; Task Scheduler Operational; registry and endpoint inventory consoles | Compare new services/tasks/Run keys and SoftEther/AnyDesk/TeamViewer inventory with the approved software and owner ledger. | Capture binary, signer/hash, configuration, owner, and business dependency before disablement. |
| Cloud, CI/CD, and Kubernetes access | Cloud audit, pipeline audit, secret-manager access, and Kubernetes API audit logs | Find new privileged pods, service-account token use, secret reads, environment exports, or control-plane changes from unexpected identities. | Freeze audit evidence and revoke only demonstrated-exposed credentials in dependency order. |
| Payment and HSM anomaly review | Pix/STR/Boleto gateway, mTLS, HSM, KMS, vault, and transaction audit consoles | Baseline signing-key use, certificate/configuration changes, unusual transaction bursts, and out-of-hours privileged access. | Escalate to fraud and payment owners; preserve transaction and signing evidence before blocking business flows. |
| WebSocket and HTTPS tunnel validation | Proxy, TLS inspection metadata, load balancer, and server HTTP logs | Join HTTP Upgrade, long-lived flows, unusual cookies, or unexpected port-443 listeners to process identity and destination prevalence. | Treat listener or WebSocket use alone as insufficient; isolate only when process and flow evidence corroborate. |
CrowdStrike LogScale CQL Hunt Queries
All queries are STATIC-ONLY and lack tenant execution evidence. Run them manually with a one-hour window first, confirm fields, then expand to the card lookback.
Looks for: known BREEZE COMET hashes in process or executable-write telemetry. Accomplishes: covers published malware hash correlation while retaining the host, process, or domain context needed for analyst verification.
// HUNT: Published malware hash correlation // HYPOTHESIS: H01 // USE: hunt // MITRE: N/A — IOC correlation // CONF: high // FP: medium // COST: low // TIMEFRAME: 90d — bounded retrospective window matched to indicator volatility and behavior // REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed // FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS // TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline // VALIDATION: STATIC-ONLY #event_simpleName = /^(ProcessRollup2|PeFileWritten|NewExecutableWritten)$/ | SHA256HashData = /^(3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec|2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a|c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a|6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb|f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f|51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6|d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66|447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8)$/i | table([@timestamp, aid, ComputerName, UserName, FileName, FilePath, ImageFileName, SHA256HashData, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: PowerShell or native utilities collecting Wi-Fi, DNS, domain-controller, and network configuration. Accomplishes: covers dense powershell and native network reconnaissance while retaining the host, process, or domain context needed for analyst verification.
// HUNT: Dense PowerShell and native network reconnaissance // HYPOTHESIS: H02 // USE: hunt // MITRE: T1016, T1087.002 // CONF: medium // FP: high // COST: medium // TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior // REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed // FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS // TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | FileName = /^(powershell|pwsh|cmd|netsh|nltest)(\.exe)?$/i | CommandLine = /(wlan\s+export\s+profile|key=clear|\/dsgetdc:|\/dclist:|Win32_NetworkAdapterConfiguration|LOGONSERVER|Get-NetIPAddress|Get-DnsClientServerAddress)/i | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: PowerShell commands combining Set-MpPreference with real-time monitoring disablement. Accomplishes: covers powershell disabling defender real-time monitoring while retaining the host, process, or domain context needed for analyst verification.
// HUNT: PowerShell disabling Defender real-time monitoring // HYPOTHESIS: H03 // USE: alert-candidate // MITRE: T1562.001 // CONF: high // FP: medium // COST: low // TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior // REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed // FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS // TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | FileName = /^(powershell|pwsh)(\.exe)?$/i | CommandLine = /Set-MpPreference[^ ]*DisableRealtimeMonitoring[^ ]*(true|\$true|1)/i | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: wevtutil or PowerShell clearing Windows event logs. Accomplishes: covers windows event-log clearing commands while retaining the host, process, or domain context needed for analyst verification.
// HUNT: Windows event-log clearing commands // HYPOTHESIS: H04 // USE: alert-candidate // MITRE: T1070.001 // CONF: high // FP: medium // COST: low // TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior // REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed // FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS // TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | FileName = /^(wevtutil|powershell|pwsh)(\.exe)?$/i | CommandLine = /(wevtutil(\.exe)?\s+(cl|clear-log)|Clear-EventLog)/i | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: shell and interpreter commands creating scheduled tasks, services, or Run-key entries. Accomplishes: covers scripted task, service, or run-key persistence while retaining the host, process, or domain context needed for analyst verification.
// HUNT: Scripted task, service, or Run-key persistence // HYPOTHESIS: H05 // USE: hunt // MITRE: T1053.005, T1543.003, T1060 // CONF: medium // FP: high // COST: medium // TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior // REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed // FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS // TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | FileName = /^(schtasks|sc|reg|powershell|pwsh|cmd)(\.exe)?$/i | CommandLine = /(schtasks(\.exe)?[^ ]*\/create|sc(\.exe)?[^ ]+create\s|New-Service|CurrentVersion\+Run(Once)?|Set-ItemProperty[^ ]*CurrentVersion\+Run)/i | table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId]) | sort(@timestamp, order=desc, limit=1000)
Looks for: AnyDesk, TeamViewer, SoftEther, and common VPN/RMM process execution requiring owner review. Accomplishes: covers remote-management and vpn execution inventory while retaining the host, process, or domain context needed for analyst verification.
// HUNT: Remote-management and VPN execution inventory // HYPOTHESIS: H06 // USE: inventory // MITRE: N/A — inventory // CONF: medium // FP: high // COST: low // TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior // REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed // FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS // TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline // VALIDATION: STATIC-ONLY #event_simpleName = ProcessRollup2 | (FileName = /^(AnyDesk|TeamViewer|vpnserver|vpnsmgr|vpnclient|RemoteUtilities|ScreenConnect\.ClientService)(\.exe)?$/i OR ImageFileName = /(AnyDesk|TeamViewer|SoftEther|Remote Utilities|ScreenConnect)/i) | groupBy([aid, ComputerName, UserName, FileName, ImageFileName, SHA256HashData], function=[count(as=Executions), min(@timestamp, as=FirstSeen), max(@timestamp, as=LastSeen)], limit=1000) | sort(LastSeen, order=desc, limit=1000)
Looks for: java or javaw DNS requests grouped by host and domain for application-aware review. Accomplishes: covers java-origin dns activity baseline while retaining the host, process, or domain context needed for analyst verification.
// HUNT: Java-origin DNS activity baseline // HYPOTHESIS: H07 // USE: hunt // MITRE: T1071.004 // CONF: low // FP: high // COST: medium // TIMEFRAME: 7d — bounded retrospective window matched to indicator volatility and behavior // REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed // FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS // TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline // VALIDATION: STATIC-ONLY #event_simpleName = DnsRequest | ContextBaseFileName = /^(java|javaw)(\.exe)?$/i | groupBy([aid, ComputerName, ContextBaseFileName, DomainName], function=[count(as=Requests), min(@timestamp, as=FirstSeen), max(@timestamp, as=LastSeen)], limit=1000) | sort(Requests, order=desc, limit=1000)
Operationalization and IOA Candidates
Every query has an explicit hunt-only decision. Q03 and Q04 retain future alert-candidate metadata, but no scheduled search or alert email is produced without tenant evidence.
| Alert | Query | Stage 3 use | Decision | Readiness | Rationale |
|---|---|---|---|---|---|
| A01 | Q01 | hunt | hunt-only | design-only | Inventory or context-dependent logic remains analyst-led. |
| A02 | Q02 | hunt | hunt-only | design-only | Inventory or context-dependent logic remains analyst-led. |
| A03 | Q03 | alert-candidate | hunt-only | design-only | Potential future alert candidate, but tenant parse, safe positive evidence, benign baseline, result prevalence, and suppression performance are absent. |
| A04 | Q04 | alert-candidate | hunt-only | design-only | Potential future alert candidate, but tenant parse, safe positive evidence, benign baseline, result prevalence, and suppression performance are absent. |
| A05 | Q05 | hunt | hunt-only | design-only | Inventory or context-dependent logic remains analyst-led. |
| A06 | Q06 | inventory | hunt-only | design-only | Inventory or context-dependent logic remains analyst-led. |
| A07 | Q07 | hunt | hunt-only | design-only | Inventory or context-dependent logic remains analyst-led. |
Detect-only IOA designs
| IOA | Source | Behavior | Pilot | Positive test | Rollback |
|---|---|---|---|---|---|
| IOA01 | Q03 / H03 | Defender disablement command semantics | detect-only design | Approved inert lab marker; no Defender change | Disable rule group and preserve configuration/evidence |
| IOA02 | Q04 / H04 | Event-log clearing command semantics | detect-only design | Approved inert lab marker; no production log clearing | Disable rule group and preserve configuration/evidence |
Machine-Readable IOC Appendix
All 22 values are source-tagged and time-bounded. Revalidate compromised legitimate hosts before operational use.
type,value,action,severity,expiration,description,tags sha256,3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec,detect,high,2026-10-01,COBALTSPIN sample,source:S01 campaign:breeze-comet sha256,2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a,detect,high,2026-10-01,REALBREEZE sample,source:S01 campaign:breeze-comet sha256,c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a,detect,high,2026-10-01,MILDFROST sample,source:S01 campaign:breeze-comet sha256,6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb,detect,high,2026-10-01,BOATBEAM sample,source:S01 campaign:breeze-comet sha256,f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f,detect,high,2026-10-01,KICKPLATE sample,source:S01 campaign:breeze-comet sha256,51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6,detect,high,2026-10-01,XWORM sample,source:S01 campaign:breeze-comet sha256,d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66,detect,high,2026-10-01,XWORM sample,source:S01 campaign:breeze-comet sha256,447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8,detect,high,2026-10-01,XWORM sample,source:S01 campaign:breeze-comet domain,procon.go.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,cmgovernadorluizrocha.ma.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,gcm.setelagoas.mg.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,minacu.go.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,conseg.ssp.go.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,suporte.camaratunapolis.sc.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,tisup.camaratunapolis.sc.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,suporte.ourinhos.sp.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,servicos.salto.sp.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,www.mrtb.gov.ng,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,credeb.gov.gn,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,sit.baer.gob.ve,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,jmcov.gov.py,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet domain,dontpad.com,enrich,medium,2026-10-01,public paste site used for exfiltration,source:S01 campaign:breeze-comet
3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec 2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a 6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f 51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6 d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66 447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8
procon.go.gov.br cmgovernadorluizrocha.ma.gov.br gcm.setelagoas.mg.gov.br minacu.go.gov.br conseg.ssp.go.gov.br suporte.camaratunapolis.sc.gov.br tisup.camaratunapolis.sc.gov.br suporte.ourinhos.sp.gov.br servicos.salto.sp.gov.br www.mrtb.gov.ng credeb.gov.gn sit.baer.gob.ve jmcov.gov.py dontpad.com
Hardening — Tiered and Deployable
- Constrain unapproved RMM, VPN, and persistence binaries (CTRL01) — Create a multiple-policy App Control base or supplemental policy in audit mode; review events, then deny unapproved RMM/VPN and user-writable executable paths on the pilot only. deployable-design Verify: Export audit results and policy state; confirm only unapproved targets would be denied. Expected: No unexplained blocks and all critical workflows pass. Rollback: Remove or disable the supplemental policy through the same management plane and verify approved software starts. Authority: S04 · Application Control for Windows, current page updated 2026-08-19.
- Protect Defender settings and security logs (CTRL02) — Enable tamper protection through the approved management plane, require documented exclusion changes, and forward security/PowerShell logs to protected central storage. deployable-design Verify: Read managed security state and confirm real-time protection, tamper protection, and forwarding remain enabled. Expected: Expected protections are enabled and central logs continue arriving. Rollback: Restore the prior approved policy from the management plane and verify protection/telemetry health. Authority: S05 · Defender PowerShell module, Windows Server 2022 view.
- Require phishing-resistant MFA for privileged and remote access (CTRL03) — Pilot phishing-resistant MFA for administrators and remote-access users; block weaker factors for the pilot only after recovery and continuity tests pass. deployable-design Verify: Review sign-in method and perform approved login, recovery, and break-glass tests. Expected: Pilot users authenticate with the approved resistant method and emergency access remains available. Rollback: Reassign the prior approved authentication policy and confirm normal and emergency sign-in. Authority: S06 · CISA Implementing Phishing-Resistant MFA, accessed 2026-09-01.
- Segment administration and payment-system paths (CTRL04) — Define identity-aware allow rules from managed jump hosts to named administration and payment resources; deny workstation-to-server RDP/SMB in the pilot segment after observed-flow review. deployable-design Verify: Compare observed flows with policy and test approved, denied, and emergency administration paths. Expected: Only approved identities and managed paths reach protected resources. Rollback: Restore the previous rule set and confirm all previously healthy critical flows recover. Authority: S07 · NIST SP 800-207 final, August 2020.
- Remove reusable secrets from pipelines and host files (CTRL05) — Replace one pilot pipeline's static credential with a short-lived workload identity or centrally brokered secret; prevent plaintext export to build logs and environment dumps. deployable-design Verify: Run the pipeline and verify short-lived identity issuance, expected resource access, no secret in logs, and revocation evidence. Expected: Pipeline succeeds with least privilege and no reusable secret exposure. Rollback: Restore the prior credential from protected escrow, revoke the pilot identity, and verify the old workflow while investigating failure. Authority: S07 · NIST SP 800-207 final, August 2020.
- Constrain uncommon DNS, WebSocket, and direct egress (CTRL06) — Force pilot servers through managed DNS and egress controls; allow documented destinations and require review for direct WebSocket, DNS, or HTTPS from uncommon binaries. deployable-design Verify: Compare permitted flows with the baseline and test application, update, DNS, and emergency paths. Expected: Only documented resolver/proxy paths remain and application health is normal. Rollback: Restore the prior egress policy and confirm service recovery; retain denied-flow evidence. Authority: S07 · NIST SP 800-207 final, August 2020.
- Harden branch access and exposed application tiers (CTRL07) — Pilot 802.1X or equivalent admission control on selected branch ports, restrict unused jacks, and apply least-privilege service identities and nonprivileged workload policies to one application tier. deployable-design Verify: Verify unauthorized test device denial, approved device access, workload identity, privilege state, and service health. Expected: Unknown devices are denied and the workload operates without excess privilege. Rollback: Return pilot ports/workload to prior approved policy and confirm approved device and service recovery. Authority: S01 · GTIG report dated 2026-09-01.
- Make persistence and anti-forensics independently auditable (CTRL08) — Forward process, task, service, registry, Defender, event-log, identity, cloud, Kubernetes, and payment control-plane audit records to protected storage with health monitoring and owner-approved retention. deployable-design Verify: Generate approved benign audit events and verify timely arrival, identity, source host, timestamp, and retention policy. Expected: Every expected test event arrives intact and missing-source monitoring fires when a test source pauses. Rollback: Revert the new forwarding route while retaining the former collector and confirm the original pipeline remains healthy. Authority: S01 · GTIG report dated 2026-09-01.
Deployable playbook · CTRL01 + CTRL02
- Confirm owners, backups, current policy exports, emergency access, and stop conditions.
- Capture read-only current application-control, Defender, telemetry, and service-health state.
- Apply audit-only application control and managed Defender/tamper policy to the pilot ring.
- Verify expected audit events, protection state, central log arrival, and critical application health.
- Approve expansion only when no unexplained critical workflow is affected.
- If a stop condition occurs, restore prior policies through the management plane and verify recovery.
- Retain policy, event, approval, health, and rollback evidence with named owners.
Containment Runbook
| Phase | Trigger | Authority | Owner | Evidence | Recovery |
|---|---|---|---|---|---|
| Activate | Q01 hash hit or corroborated Q03/Q04 behavior | Incident Commander | SOC | original query result, raw event IDs, affected host/user | confirm semantics and business role before disruption |
| Preserve | activation accepted | Incident Commander | DFIR | raw process tree, files/hashes, DNS/network, task/service/registry state, identity sessions, relevant configs and tool logs | hash and store evidence before isolation, restart, or cleanup |
| Contain | malicious behavior or published hash corroborated | Incident Commander plus service owner | Endpoint, Identity, and Network teams | isolation, session revocation, egress, and exception records | maintain payment/branch continuity and approved emergency access |
| Scope | initial containment stable | Incident Commander | Threat Hunting | environment-wide Q01-Q07 results, related identities, destinations, persistence, and secrets exposure | expand containment only on evidence, not alias or tool name alone |
| Eradicate | scope and evidence preserved | Change authority and system owner | Platform and Endpoint teams | clean rebuild, removed persistence, rotated demonstrated-exposed credentials, hardened policies | use known-good backups and tested dependency order |
| Recover and Close | eradication complete and owners approve restoration | Incident Commander and business owner | Operations and IR lead | service/transaction health, identity checks, clean re-hunt at 24h/7d/30d, closure record | reopen on new hash, persistence, tunnel, identity, or transaction evidence |
Continuity rule: do not automatically isolate payment infrastructure, revoke all identities, rotate every certificate, or disable financial services. Preserve evidence, identify demonstrated exposure, and use the incident commander plus business owner for each disruptive step.
Detection Coverage and Validation Evidence
Validation state: STATIC REVIEW PASSED after local structure/safety, maintained-field, CQL heuristic, IOC provenance, and duplicate checks. This is not Falcon parsing or tenant-behavior evidence.
| Technique | Coverage | Queries | Evidence | Limitation |
|---|---|---|---|---|
| T1566 | Gap | No portable primary query | Platform-native or tenant-specific telemetry required | See native hunts and H08 gap |
| T1016 | Static | Q02 | Static-only local review | Tenant parse, positive canary, and benign baseline absent |
| T1021.001 | Gap | No portable primary query | Platform-native or tenant-specific telemetry required | See native hunts and H08 gap |
| T1021.002 | Gap | No portable primary query | Platform-native or tenant-specific telemetry required | See native hunts and H08 gap |
| T1572 | Gap | No portable primary query | Platform-native or tenant-specific telemetry required | See native hunts and H08 gap |
| T1071.004 | Static | Q07 | Static-only local review | Tenant parse, positive canary, and benign baseline absent |
| T1562.001 | Static | Q03 | Static-only local review | Tenant parse, positive canary, and benign baseline absent |
| T1070.001 | Static | Q04 | Static-only local review | Tenant parse, positive canary, and benign baseline absent |
| T1053.005 | Static | Q05 | Static-only local review | Tenant parse, positive canary, and benign baseline absent |
| T1543.003 | Static | Q05 | Static-only local review | Tenant parse, positive canary, and benign baseline absent |
Recorded evidence and gaps
- Tenant execution evidence is absent; no query is described as parsed, tested, validated, or deployed.
- The offline tenant-validation dry run records extraction and profile blockers only and does not contact Falcon.
- H08 remains a gap for WebSocket SOCKS5 and cookie-gated HTTPS semantics.
- Identity, RDP/SMB, cloud, CI/CD, Kubernetes, HSM, mTLS, and payment-transaction coverage requires platform-native schemas.
- Next step: run Q03 and Q04 manually in the intended repository for one hour, confirm returned fields, then execute safe positive and representative benign tests before scheduling.
Hunt Summary Ticket
TITLE: BREEZE COMET / UNC5669 financial-system intrusion hunt — v0.3 Draft SEVERITY: high — active, developing operations combine financial-system access with custom backdoors and defense evasion SCOPE: Falcon endpoint process/DNS telemetry; platform-native identity, network, cloud, Kubernetes, HSM, and payment logs where available HYPOTHESIS: H01 hash correlation; H02 reconnaissance; H03 Defender impairment; H04 log clearing; H05 persistence; H06 RMM/VPN inventory; H07 Java DNS; H08 tunnel gap QUERIES RUN: Q06 inventory; Q01/Q02/Q05/Q07 hunt; Q03/Q04 alert-candidate designs retained as hunt-only DO FIRST: Q03 and Q04 over 30 days, then same-host Q01/Q02/Q05/Q06/Q07 pivots FINDINGS: GAPS: tenant parse/canary/baseline absent; encrypted tunnel, identity, cloud, Kubernetes, HSM, and payment schemas not mapped ACTIONS: SOC validates Q03/Q04 fields; Detection Engineering records positive/benign tests; service owners review CTRL01-CTRL08 pilots OWNER: SOC / Detection Engineering / Endpoint, Identity, Network, Platform, and Payment owners VERSION: v0.3 Draft · 2026-09-04 · STATIC REVIEW PASSED