BREEZE COMET Financial-System Intrusions

UNC5669 / Plump Spider / SHADOW-AETHER-064 · custom backdoors, financial fraud, detection, response, and hardening
Threat
BREEZE COMET / UNC5669
Type
Financial-system intrusion and custom backdoors
Severity
High · active and developing
Version
v0.3 Draft · 2026-09-04
Author
cybersecurity analyst
Confidence
High for core activity; medium for single-source malware details
STATIC REVIEW PASSED
01

Executive Summary

What happened: Google Threat Intelligence Group and Mandiant reported on 1 September 2026 that the financially motivated actor BREEZE COMET, formerly UNC5669 and overlapping Plump Spider and SHADOW-AETHER-064, has compromised Brazilian financial services, retail, ecommerce, payment, and related environments since 2024. Axur independently documented the actor's IT-support impersonation and a PowerShell reconnaissance payload used against the Pix ecosystem. The objective is access to payment workflows, mTLS credentials, privileged identities, and the infrastructure needed to conduct fraudulent transfers.

How the intrusion works: footholds have included voice-based IT impersonation, coerced RMM installation, compromised government websites staging XWORM and other payloads, exploitation of JBoss AS servers, password spraying, and rogue hardware attached to retail networks. The actor then uses PowerShell and native utilities to inventory hosts, Wi-Fi keys, DNS, domain controllers, cloud and CI/CD secrets, and payment-related files. RDP and SMB support lateral movement. Its redundant custom access stack includes REALBREEZE for LDAP brute forcing; COBALTSPIN, a Rust reverse SOCKS5 proxy over WebSocket; LIGHTPAINT, which installs SoftEther and opens inbound firewall paths; MILDFROST, a Java JAR backdoor using delegated DNS; KICKPLATE, which modifies services and Run keys; and BOATBEAM, which imitates IIS HTTPS on port 443 and activates on a session cookie. Persistence also uses scheduled tasks and startup shortcuts. Observed anti-forensics include disabling Defender real-time monitoring and clearing Windows logs.

Why detection lives in behavior: the eight published hashes provide high-confidence retrospective pivots, but the government-host staging domains are compromised legitimate infrastructure and can be remediated or reused. The more durable Falcon signals are Defender disablement, log clearing, dense PowerShell/network reconnaissance, scripted persistence, and unapproved RMM/VPN execution. DNS from Java is a baseline-driven lead, not proof of MILDFROST. WebSocket SOCKS5 and cookie-gated HTTPS semantics remain a telemetry gap unless process events can be joined to proxy or HTTP evidence.

Defender priority: run Q03 and Q04 across 30 days first, then correlate Q01, Q02, Q05, Q06, and Q07 on the same hosts before any containment or credential action.
PriorityWhy nowCoverage deliveredKey limitation
Find defense impairment and anti-forensics, then pivotActive, developing intrusions target financial workflows7 CQL queries: 1 inventory, 4 hunts, 2 alert candidatesStatic review only; encrypted tunnel, identity, cloud, Kubernetes, and payment telemetry need tenant-specific validation
02

Source and Claim Review

Seven current-run sanitized snapshots preserve three independent research streams and four hardening authorities. S03 is visibly partial and supports only alias/corroboration context.

IDPublisherTierIndependence groupAccessedStatus
S01Google Threat Intelligence Group / Mandiantprimary-incident-responsegoogle-mandiant2026-09-01T11:04:14Zcomplete-sanitized
S02Axur Research Teamprimary-researchaxur2026-09-01T11:04:14Zcomplete-sanitized
S03Trend Micro Researchprimary-researchtrend-micro2026-09-01T11:04:14Zpartial-sanitized
S04Microsoft Learnprimary-vendor-guidancemicrosoft2026-09-01T11:04:14Zcomplete-sanitized
S05Microsoft Learnprimary-vendor-guidancemicrosoft2026-09-01T11:04:14Zcomplete-sanitized
S06CISAgovernment-guidancecisa2026-09-01T11:04:14Zcomplete-sanitized
S07NISTgovernment-guidancenist2026-09-01T11:04:14Zcomplete-sanitized

Claim ledger

ClaimStatementSourcesConfidenceContradiction
C01BREEZE COMET, formerly UNC5669, overlaps activity reported as Plump Spider and SHADOW-AETHER-064.S01, S02, S03highnone
C02The actor compromises financial services, retail, ecommerce, payment, and related environments to enable fraudulent transfers.S01, S02highnone
C03Observed initial access includes voice-based IT impersonation and coerced installation of remote-management or reconnaissance tooling.S01, S02highnone
C04Separate reporting links the activity to compromised web infrastructure and exploitation of JBoss AS servers.S01, S03mediumnone
C05Reconnaissance collected host, user, domain, DNS, network, Wi-Fi credential, and domain-controller data using PowerShell and native utilities.S01, S02highnone
C06The actor used RDP and SMB with hijacked accounts and deployed network-scanning tools for lateral movement.S01mediumnone
C07COBALTSPIN provides a reverse SOCKS5 proxy over WebSocket for routing traffic through segmented networks.S01mediumnone
C08LIGHTPAINT installs a VPN such as SoftEther, adds inbound firewall rules, and clears related Windows networking logs.S01mediumnone
C09MILDFROST is a Java JAR backdoor that uses delegated DNS subdomains for covert command and control.S01mediumnone
C10KICKPLATE modifies registry startup keys and Windows services and controls SOCKS5 tunnelers.S01mediumnone
C11BOATBEAM exposes an imitation IIS HTTPS service on port 443 and activates C2 behavior on a specific session cookie.S01mediumnone
C12Observed defense evasion includes disabling Windows Defender real-time monitoring and clearing Windows event logs.S01mediumnone
C13The actor searched hosts and environment variables for mTLS certificates, payment-related terms, pipeline credentials, API keys, and cloud tokens.S01, S02mediumnone
C14The actor used scheduled tasks, malicious startup shortcuts, and Windows service modifications for persistence.S01mediumnone
C15Google published eight SHA-256 malware indicators associated with COBALTSPIN, REALBREEZE, MILDFROST, BOATBEAM, KICKPLATE, and XWORM.S01highnone
C16Google published compromised government-host infrastructure used for malware staging or command and control.S01highnone
C17Mandiant observed the actor using AI-assisted scripts for reconnaissance, credential validation, deployment, pivoting, and data extraction.S01mediumnone
Evidence limits: named malware roles are single-source details; compromised government hosts are volatile; S03 technical details were excluded because its body was only partially retrievable.
03

Hunt Brief and Attack Chain

The scaffold separates foothold, reconnaissance, movement, C2, persistence, defense evasion, and financial-objective coverage so missing telemetry cannot masquerade as detection.

StepClaimsBehaviorPlatformDetection goal
1C03, C04social engineering, trusted-web staging, server exploitation, or rogue-device footholdcross-platformidentify user-driven shell/RMM activity and known staging infrastructure
2C05, C13host, network, domain, credential, CI/CD, and secret reconnaissancecross-platformdetect dense native-utility and PowerShell reconnaissance
3C06RDP and SMB lateral movement using hijacked accountswindowscorrelate endpoint execution with tenant authentication/network evidence
4C07, C09, C11redundant WebSocket, DNS, and HTTPS command-and-control channelscross-platformfind uncommon process/network pairings and document portable telemetry gaps
5C08, C10, C14VPN, scheduled-task, startup, registry, and service persistencewindowsfind unapproved VPN/RMM and persistence-control changes
6C12endpoint protection impairment and event-log clearingwindowsdetect defender preference changes and anti-forensic commands
7C02, C13use of stolen credentials and financial workflows for fraudulent transfersidentity/cloud/financial applicationhand off to identity, secrets, HSM, and payment-system owners where portable endpoint telemetry ends

Hypotheses

IDBehaviorTelemetryUseLookbackValidation
H01known malware hash presenceProcessRollup2, PeFileWritten, NewExecutableWrittenhunt90d — low-volatility hashes support a longer retrospective windowUse a synthetic non-malicious hash equality check against a controlled test event or known tenant sample; baseline security-lab hosts separately.
H02PowerShell and native-utility network/domain reconnaissanceProcessRollup2hunt30d — covers current activity while bounding command-line scan costRun isolated benign commands that emit the targeted argument shapes, then compare against a 30-day help-desk and network-administration baseline.
H03PowerShell disabling Defender real-time monitoringProcessRollup2alert-candidate30d — defense impairment is high-value and should be retained for incident reviewUse an approved isolated lab with a harmless command-line marker that does not change Defender state; baseline authorized security tooling and maintenance accounts.
H04Windows event-log clearingProcessRollup2alert-candidate30d — anti-forensic behavior should remain visible through incident scopingGenerate an approved inert command-line marker in an isolated test host; baseline legitimate image-build and troubleshooting activity without clearing production logs.
H05scripted task, service, or Run-key persistenceProcessRollup2hunt30d — persistence changes may precede later fraudulent activityUse nonpersistent dry-run markers in an isolated host and baseline approved deployment-tool parents, signers, accounts, and destinations.
H06unapproved RMM or VPN executionProcessRollup2inventory30d — supports inventory and incident correlationRun against a known approved-software inventory and verify that allowlisting by managed path, signer, and owner separates sanctioned deployments.
H07Java process DNS-tunneling leadDnsRequesthunt7d — DNS volume aggregation should stay bounded and recentConfirm DnsRequest process attribution on a known Java workload, then build a seven-day per-application domain and volume baseline before judging outliers.
H08WebSocket SOCKS5 or cookie-gated HTTPS tunnelingproxy, network sensor, server HTTP logs, or tenant-specific Falcon network telemetrygap14d — current intrusion-scoping windowIn an isolated lab, capture known-benign WebSocket and SOCKS5 traffic plus a controlled tunnel; document proxy/EDR field mapping before designing CQL.

Affected surface and telemetry

The pack assumes broadly available endpoint process telemetry plus DNS events where populated. Network, identity, CI/CD, cloud, Kubernetes, proxy/HTTP, HSM, and payment-system logs are not assumed. Linux process and path variants, IPv6, wrapper lineage, DNS process attribution, and all parser-specific fields require confirmation in the intended repository.

04

Consolidated IOC Table

IDTypeValueContextSourceConfidenceVolatilityAction
I01sha2563b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceecCOBALTSPIN sampleS01highlowdetect
I02sha2562214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439aREALBREEZE sampleS01highlowdetect
I03sha256c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78aMILDFROST sampleS01highlowdetect
I04sha2566d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6cebBOATBEAM sampleS01highlowdetect
I05sha256f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4fKICKPLATE sampleS01highlowdetect
I06sha25651fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6XWORM sampleS01highlowdetect
I07sha256d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66XWORM sampleS01highlowdetect
I08sha256447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8XWORM sampleS01highlowdetect
I09domainprocon.go.gov.brcompromised staging hostS01mediumhighenrich
I10domaincmgovernadorluizrocha.ma.gov.brcompromised staging hostS01mediumhighenrich
I11domaingcm.setelagoas.mg.gov.brcompromised staging hostS01mediumhighenrich
I12domainminacu.go.gov.brcompromised staging hostS01mediumhighenrich
I13domainconseg.ssp.go.gov.brcompromised staging hostS01mediumhighenrich
I14domainsuporte.camaratunapolis.sc.gov.brcompromised staging hostS01mediumhighenrich
I15domaintisup.camaratunapolis.sc.gov.brcompromised staging hostS01mediumhighenrich
I16domainsuporte.ourinhos.sp.gov.brcompromised staging hostS01mediumhighenrich
I17domainservicos.salto.sp.gov.brcompromised staging hostS01mediumhighenrich
I18domainwww.mrtb.gov.ngcompromised staging hostS01mediumhighenrich
I19domaincredeb.gov.gncompromised staging hostS01mediumhighenrich
I20domainsit.baer.gob.vecompromised staging hostS01mediumhighenrich
I21domainjmcov.gov.pycompromised staging hostS01mediumhighenrich
I22domaindontpad.compublic paste site used for exfiltrationS01mediumhighpivot
No blind blocking: the listed government and paste-site domains may be legitimate, compromised, or already remediated. Use them for time-bounded enrichment and same-host correlation; start hashes in detect mode pending local review.
05

ATT&CK Mapping

Mappings below are analyst inferences from source-backed behavior. IOC correlation and product inventory are intentionally unmapped.

TacticTechniqueNameBehaviorBasisSourcesClaims
Initial AccessT1566PhishingIT-support impersonation induced users to install attacker-selected toolinganalyst inferenceS01, S02C03
DiscoveryT1016System Network Configuration Discoveryscripts collected IP, DNS, adapter, gateway, and domain-controller dataanalyst inferenceS01, S02C05
Lateral MovementT1021.001Remote Services: RDPhijacked accounts initiated unauthorized RDP sessionsanalyst inferenceS01C06
Lateral MovementT1021.002Remote Services: SMB/Windows Admin Sharescommands were executed through SMB network sharesanalyst inferenceS01C06
Command and ControlT1572Protocol TunnelingCOBALTSPIN routes SOCKS5 traffic through WebSocketanalyst inferenceS01C07
Command and ControlT1071.004Application Layer Protocol: DNSMILDFROST uses DNS tunnelinganalyst inferenceS01C09
Defense EvasionT1562.001Impair DefensesPowerShell disabled Defender real-time monitoringanalyst inferenceS01C12
Defense EvasionT1070.001Clear Windows Event Logsthe actor cleared event logsanalyst inferenceS01C12
PersistenceT1053.005Scheduled Task/Job: Scheduled Taskscheduled tasks ran as SYSTEManalyst inferenceS01C14
PersistenceT1543.003Create or Modify System Process: Windows Serviceservices were modified for persistenceanalyst inferenceS01C14
06

Native / Non-CQL Hunts

Platform-native review is required where portable endpoint CQL ends.

HuntLog sourceLogicResponse
Privileged identity and lateral movementWindows Security 4624/4625/4672, 4720/4728/4732/4756, 4662, 5136, and RDP/SMB telemetryFind password-spray-to-success patterns, unexpected privileged-group changes, DCSync-like directory access, and RDP/SMB from unusual sources.Preserve raw events and session identifiers; correlate to the endpoint timeline before revocation.
RMM, VPN, task, service, and Run-key persistenceWindows Service Control Manager 7045; Task Scheduler Operational; registry and endpoint inventory consolesCompare new services/tasks/Run keys and SoftEther/AnyDesk/TeamViewer inventory with the approved software and owner ledger.Capture binary, signer/hash, configuration, owner, and business dependency before disablement.
Cloud, CI/CD, and Kubernetes accessCloud audit, pipeline audit, secret-manager access, and Kubernetes API audit logsFind new privileged pods, service-account token use, secret reads, environment exports, or control-plane changes from unexpected identities.Freeze audit evidence and revoke only demonstrated-exposed credentials in dependency order.
Payment and HSM anomaly reviewPix/STR/Boleto gateway, mTLS, HSM, KMS, vault, and transaction audit consolesBaseline signing-key use, certificate/configuration changes, unusual transaction bursts, and out-of-hours privileged access.Escalate to fraud and payment owners; preserve transaction and signing evidence before blocking business flows.
WebSocket and HTTPS tunnel validationProxy, TLS inspection metadata, load balancer, and server HTTP logsJoin HTTP Upgrade, long-lived flows, unusual cookies, or unexpected port-443 listeners to process identity and destination prevalence.Treat listener or WebSocket use alone as insufficient; isolate only when process and flow evidence corroborate.
07

CrowdStrike LogScale CQL Hunt Queries

Pick your tenant's cloud first — every "Open in Falcon" button below uses this selection.
Query strategy: Q03 and Q04 are the strongest behavioral keepers. Q01 is high-confidence IOC correlation; Q02, Q05, and Q07 need same-host or application-aware correlation; Q06 is inventory only.

All queries are STATIC-ONLY and lack tenant execution evidence. Run them manually with a one-hour window first, confirm fields, then expand to the card lookback.

Q01 · known BREEZE COMET hashes in process or executable-write telemetry
CONF highFP mediumCOST low

Looks for: known BREEZE COMET hashes in process or executable-write telemetry. Accomplishes: covers published malware hash correlation while retaining the host, process, or domain context needed for analyst verification.

Trace: H01 · A01

// HUNT: Published malware hash correlation
// HYPOTHESIS: H01
// USE: hunt
// MITRE: N/A — IOC correlation
// CONF: high
// FP: medium
// COST: low
// TIMEFRAME: 90d — bounded retrospective window matched to indicator volatility and behavior
// REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed
// FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS
// TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline
// VALIDATION: STATIC-ONLY
#event_simpleName = /^(ProcessRollup2|PeFileWritten|NewExecutableWritten)$/
| SHA256HashData = /^(3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec|2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a|c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a|6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb|f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f|51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6|d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66|447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8)$/i
| table([@timestamp, aid, ComputerName, UserName, FileName, FilePath, ImageFileName, SHA256HashData, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q02 · PowerShell or native utilities collecting Wi-Fi, DNS, domain-controller, and network configuration
CONF mediumFP highCOST medium

Looks for: PowerShell or native utilities collecting Wi-Fi, DNS, domain-controller, and network configuration. Accomplishes: covers dense powershell and native network reconnaissance while retaining the host, process, or domain context needed for analyst verification.

Trace: H02 · A02

// HUNT: Dense PowerShell and native network reconnaissance
// HYPOTHESIS: H02
// USE: hunt
// MITRE: T1016, T1087.002
// CONF: medium
// FP: high
// COST: medium
// TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior
// REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed
// FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS
// TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| FileName = /^(powershell|pwsh|cmd|netsh|nltest)(\.exe)?$/i
| CommandLine = /(wlan\s+export\s+profile|key=clear|\/dsgetdc:|\/dclist:|Win32_NetworkAdapterConfiguration|LOGONSERVER|Get-NetIPAddress|Get-DnsClientServerAddress)/i
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q03 · PowerShell commands combining Set-MpPreference with real-time monitoring disablement
CONF highFP mediumCOST low

Looks for: PowerShell commands combining Set-MpPreference with real-time monitoring disablement. Accomplishes: covers powershell disabling defender real-time monitoring while retaining the host, process, or domain context needed for analyst verification.

Trace: H03 · A03

// HUNT: PowerShell disabling Defender real-time monitoring
// HYPOTHESIS: H03
// USE: alert-candidate
// MITRE: T1562.001
// CONF: high
// FP: medium
// COST: low
// TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior
// REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed
// FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS
// TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| FileName = /^(powershell|pwsh)(\.exe)?$/i
| CommandLine = /Set-MpPreference[^
]*DisableRealtimeMonitoring[^
]*(true|\$true|1)/i
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q04 · wevtutil or PowerShell clearing Windows event logs
CONF highFP mediumCOST low

Looks for: wevtutil or PowerShell clearing Windows event logs. Accomplishes: covers windows event-log clearing commands while retaining the host, process, or domain context needed for analyst verification.

Trace: H04 · A04

// HUNT: Windows event-log clearing commands
// HYPOTHESIS: H04
// USE: alert-candidate
// MITRE: T1070.001
// CONF: high
// FP: medium
// COST: low
// TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior
// REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed
// FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS
// TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| FileName = /^(wevtutil|powershell|pwsh)(\.exe)?$/i
| CommandLine = /(wevtutil(\.exe)?\s+(cl|clear-log)|Clear-EventLog)/i
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q05 · shell and interpreter commands creating scheduled tasks, services, or Run-key entries
CONF mediumFP highCOST medium

Looks for: shell and interpreter commands creating scheduled tasks, services, or Run-key entries. Accomplishes: covers scripted task, service, or run-key persistence while retaining the host, process, or domain context needed for analyst verification.

Trace: H05 · A05

// HUNT: Scripted task, service, or Run-key persistence
// HYPOTHESIS: H05
// USE: hunt
// MITRE: T1053.005, T1543.003, T1060
// CONF: medium
// FP: high
// COST: medium
// TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior
// REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed
// FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS
// TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| FileName = /^(schtasks|sc|reg|powershell|pwsh|cmd)(\.exe)?$/i
| CommandLine = /(schtasks(\.exe)?[^
]*\/create|sc(\.exe)?[^
]+create\s|New-Service|CurrentVersion\+Run(Once)?|Set-ItemProperty[^
]*CurrentVersion\+Run)/i
| table([@timestamp, aid, ComputerName, UserName, FileName, ImageFileName, ParentBaseFileName, CommandLine, ParentProcessId, TargetProcessId])
| sort(@timestamp, order=desc, limit=1000)
Q06 · AnyDesk, TeamViewer, SoftEther, and common VPN/RMM process execution requiring owner review
CONF mediumFP highCOST low

Looks for: AnyDesk, TeamViewer, SoftEther, and common VPN/RMM process execution requiring owner review. Accomplishes: covers remote-management and vpn execution inventory while retaining the host, process, or domain context needed for analyst verification.

Trace: H06 · A06

// HUNT: Remote-management and VPN execution inventory
// HYPOTHESIS: H06
// USE: inventory
// MITRE: N/A — inventory
// CONF: medium
// FP: high
// COST: low
// TIMEFRAME: 30d — bounded retrospective window matched to indicator volatility and behavior
// REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed
// FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS
// TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline
// VALIDATION: STATIC-ONLY
#event_simpleName = ProcessRollup2
| (FileName = /^(AnyDesk|TeamViewer|vpnserver|vpnsmgr|vpnclient|RemoteUtilities|ScreenConnect\.ClientService)(\.exe)?$/i OR ImageFileName = /(AnyDesk|TeamViewer|SoftEther|Remote Utilities|ScreenConnect)/i)
| groupBy([aid, ComputerName, UserName, FileName, ImageFileName, SHA256HashData], function=[count(as=Executions), min(@timestamp, as=FirstSeen), max(@timestamp, as=LastSeen)], limit=1000)
| sort(LastSeen, order=desc, limit=1000)
Q07 · java or javaw DNS requests grouped by host and domain for application-aware review
CONF lowFP highCOST medium

Looks for: java or javaw DNS requests grouped by host and domain for application-aware review. Accomplishes: covers java-origin dns activity baseline while retaining the host, process, or domain context needed for analyst verification.

Trace: H07 · A07

// HUNT: Java-origin DNS activity baseline
// HYPOTHESIS: H07
// USE: hunt
// MITRE: T1071.004
// CONF: low
// FP: high
// COST: medium
// TIMEFRAME: 7d — bounded retrospective window matched to indicator volatility and behavior
// REQUIRES: Falcon endpoint event repository; event types and fields shown below; tenant field population must be confirmed
// FALSE POSITIVES: Security labs, approved administrators, software deployment, help-desk diagnostics, sanctioned RMM/VPN, and Java application DNS
// TUNING: Exclude only approved administrator accounts, managed deployment parents, sanctioned paths, and known application domains after measuring a benign baseline
// VALIDATION: STATIC-ONLY
#event_simpleName = DnsRequest
| ContextBaseFileName = /^(java|javaw)(\.exe)?$/i
| groupBy([aid, ComputerName, ContextBaseFileName, DomainName], function=[count(as=Requests), min(@timestamp, as=FirstSeen), max(@timestamp, as=LastSeen)], limit=1000)
| sort(Requests, order=desc, limit=1000)
08

Operationalization and IOA Candidates

Every query has an explicit hunt-only decision. Q03 and Q04 retain future alert-candidate metadata, but no scheduled search or alert email is produced without tenant evidence.

AlertQueryStage 3 useDecisionReadinessRationale
A01Q01hunthunt-onlydesign-onlyInventory or context-dependent logic remains analyst-led.
A02Q02hunthunt-onlydesign-onlyInventory or context-dependent logic remains analyst-led.
A03Q03alert-candidatehunt-onlydesign-onlyPotential future alert candidate, but tenant parse, safe positive evidence, benign baseline, result prevalence, and suppression performance are absent.
A04Q04alert-candidatehunt-onlydesign-onlyPotential future alert candidate, but tenant parse, safe positive evidence, benign baseline, result prevalence, and suppression performance are absent.
A05Q05hunthunt-onlydesign-onlyInventory or context-dependent logic remains analyst-led.
A06Q06inventoryhunt-onlydesign-onlyInventory or context-dependent logic remains analyst-led.
A07Q07hunthunt-onlydesign-onlyInventory or context-dependent logic remains analyst-led.

Detect-only IOA designs

IOASourceBehaviorPilotPositive testRollback
IOA01Q03 / H03Defender disablement command semanticsdetect-only designApproved inert lab marker; no Defender changeDisable rule group and preserve configuration/evidence
IOA02Q04 / H04Event-log clearing command semanticsdetect-only designApproved inert lab marker; no production log clearingDisable rule group and preserve configuration/evidence
09

Machine-Readable IOC Appendix

All 22 values are source-tagged and time-bounded. Revalidate compromised legitimate hosts before operational use.

Falcon review CSV22 rows
type,value,action,severity,expiration,description,tags
sha256,3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec,detect,high,2026-10-01,COBALTSPIN sample,source:S01 campaign:breeze-comet
sha256,2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a,detect,high,2026-10-01,REALBREEZE sample,source:S01 campaign:breeze-comet
sha256,c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a,detect,high,2026-10-01,MILDFROST sample,source:S01 campaign:breeze-comet
sha256,6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb,detect,high,2026-10-01,BOATBEAM sample,source:S01 campaign:breeze-comet
sha256,f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f,detect,high,2026-10-01,KICKPLATE sample,source:S01 campaign:breeze-comet
sha256,51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6,detect,high,2026-10-01,XWORM sample,source:S01 campaign:breeze-comet
sha256,d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66,detect,high,2026-10-01,XWORM sample,source:S01 campaign:breeze-comet
sha256,447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8,detect,high,2026-10-01,XWORM sample,source:S01 campaign:breeze-comet
domain,procon.go.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,cmgovernadorluizrocha.ma.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,gcm.setelagoas.mg.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,minacu.go.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,conseg.ssp.go.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,suporte.camaratunapolis.sc.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,tisup.camaratunapolis.sc.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,suporte.ourinhos.sp.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,servicos.salto.sp.gov.br,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,www.mrtb.gov.ng,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,credeb.gov.gn,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,sit.baer.gob.ve,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,jmcov.gov.py,enrich,medium,2026-10-01,compromised staging host,source:S01 campaign:breeze-comet
domain,dontpad.com,enrich,medium,2026-10-01,public paste site used for exfiltration,source:S01 campaign:breeze-comet
Malware SHA-2568 values
3b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec
2214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a
c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a
6d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb
f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f
51fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6
d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66
447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8
Compromised / abused hosts14 values
procon.go.gov.br
cmgovernadorluizrocha.ma.gov.br
gcm.setelagoas.mg.gov.br
minacu.go.gov.br
conseg.ssp.go.gov.br
suporte.camaratunapolis.sc.gov.br
tisup.camaratunapolis.sc.gov.br
suporte.ourinhos.sp.gov.br
servicos.salto.sp.gov.br
www.mrtb.gov.ng
credeb.gov.gn
sit.baer.gob.ve
jmcov.gov.py
dontpad.com
10

Hardening — Tiered and Deployable

Immediate — stop easy persistence and defense impairment
  • Constrain unapproved RMM, VPN, and persistence binaries (CTRL01) — Create a multiple-policy App Control base or supplemental policy in audit mode; review events, then deny unapproved RMM/VPN and user-writable executable paths on the pilot only. deployable-design Verify: Export audit results and policy state; confirm only unapproved targets would be denied. Expected: No unexplained blocks and all critical workflows pass. Rollback: Remove or disable the supplemental policy through the same management plane and verify approved software starts. Authority: S04 · Application Control for Windows, current page updated 2026-08-19.
  • Protect Defender settings and security logs (CTRL02) — Enable tamper protection through the approved management plane, require documented exclusion changes, and forward security/PowerShell logs to protected central storage. deployable-design Verify: Read managed security state and confirm real-time protection, tamper protection, and forwarding remain enabled. Expected: Expected protections are enabled and central logs continue arriving. Rollback: Restore the prior approved policy from the management plane and verify protection/telemetry health. Authority: S05 · Defender PowerShell module, Windows Server 2022 view.
Near-term — harden identity, secrets, and movement paths
  • Require phishing-resistant MFA for privileged and remote access (CTRL03) — Pilot phishing-resistant MFA for administrators and remote-access users; block weaker factors for the pilot only after recovery and continuity tests pass. deployable-design Verify: Review sign-in method and perform approved login, recovery, and break-glass tests. Expected: Pilot users authenticate with the approved resistant method and emergency access remains available. Rollback: Reassign the prior approved authentication policy and confirm normal and emergency sign-in. Authority: S06 · CISA Implementing Phishing-Resistant MFA, accessed 2026-09-01.
  • Segment administration and payment-system paths (CTRL04) — Define identity-aware allow rules from managed jump hosts to named administration and payment resources; deny workstation-to-server RDP/SMB in the pilot segment after observed-flow review. deployable-design Verify: Compare observed flows with policy and test approved, denied, and emergency administration paths. Expected: Only approved identities and managed paths reach protected resources. Rollback: Restore the previous rule set and confirm all previously healthy critical flows recover. Authority: S07 · NIST SP 800-207 final, August 2020.
  • Remove reusable secrets from pipelines and host files (CTRL05) — Replace one pilot pipeline's static credential with a short-lived workload identity or centrally brokered secret; prevent plaintext export to build logs and environment dumps. deployable-design Verify: Run the pipeline and verify short-lived identity issuance, expected resource access, no secret in logs, and revocation evidence. Expected: Pipeline succeeds with least privilege and no reusable secret exposure. Rollback: Restore the prior credential from protected escrow, revoke the pilot identity, and verify the old workflow while investigating failure. Authority: S07 · NIST SP 800-207 final, August 2020.
Strategic — constrain tunnels and make control-plane changes auditable
  • Constrain uncommon DNS, WebSocket, and direct egress (CTRL06) — Force pilot servers through managed DNS and egress controls; allow documented destinations and require review for direct WebSocket, DNS, or HTTPS from uncommon binaries. deployable-design Verify: Compare permitted flows with the baseline and test application, update, DNS, and emergency paths. Expected: Only documented resolver/proxy paths remain and application health is normal. Rollback: Restore the prior egress policy and confirm service recovery; retain denied-flow evidence. Authority: S07 · NIST SP 800-207 final, August 2020.
  • Harden branch access and exposed application tiers (CTRL07) — Pilot 802.1X or equivalent admission control on selected branch ports, restrict unused jacks, and apply least-privilege service identities and nonprivileged workload policies to one application tier. deployable-design Verify: Verify unauthorized test device denial, approved device access, workload identity, privilege state, and service health. Expected: Unknown devices are denied and the workload operates without excess privilege. Rollback: Return pilot ports/workload to prior approved policy and confirm approved device and service recovery. Authority: S01 · GTIG report dated 2026-09-01.
  • Make persistence and anti-forensics independently auditable (CTRL08) — Forward process, task, service, registry, Defender, event-log, identity, cloud, Kubernetes, and payment control-plane audit records to protected storage with health monitoring and owner-approved retention. deployable-design Verify: Generate approved benign audit events and verify timely arrival, identity, source host, timestamp, and retention policy. Expected: Every expected test event arrives intact and missing-source monitoring fires when a test source pauses. Rollback: Revert the new forwarding route while retaining the former collector and confirm the original pipeline remains healthy. Authority: S01 · GTIG report dated 2026-09-01.

Deployable playbook · CTRL01 + CTRL02

  1. Confirm owners, backups, current policy exports, emergency access, and stop conditions.
  2. Capture read-only current application-control, Defender, telemetry, and service-health state.
  3. Apply audit-only application control and managed Defender/tamper policy to the pilot ring.
  4. Verify expected audit events, protection state, central log arrival, and critical application health.
  5. Approve expansion only when no unexplained critical workflow is affected.
  6. If a stop condition occurs, restore prior policies through the management plane and verify recovery.
  7. Retain policy, event, approval, health, and rollback evidence with named owners.
Design state: no control is canary-tested or deployed. Commands and policy objects must be produced and reviewed for the named platform and tenant before execution.
11

Containment Runbook

PhaseTriggerAuthorityOwnerEvidenceRecovery
ActivateQ01 hash hit or corroborated Q03/Q04 behaviorIncident CommanderSOCoriginal query result, raw event IDs, affected host/userconfirm semantics and business role before disruption
Preserveactivation acceptedIncident CommanderDFIRraw process tree, files/hashes, DNS/network, task/service/registry state, identity sessions, relevant configs and tool logshash and store evidence before isolation, restart, or cleanup
Containmalicious behavior or published hash corroboratedIncident Commander plus service ownerEndpoint, Identity, and Network teamsisolation, session revocation, egress, and exception recordsmaintain payment/branch continuity and approved emergency access
Scopeinitial containment stableIncident CommanderThreat Huntingenvironment-wide Q01-Q07 results, related identities, destinations, persistence, and secrets exposureexpand containment only on evidence, not alias or tool name alone
Eradicatescope and evidence preservedChange authority and system ownerPlatform and Endpoint teamsclean rebuild, removed persistence, rotated demonstrated-exposed credentials, hardened policiesuse known-good backups and tested dependency order
Recover and Closeeradication complete and owners approve restorationIncident Commander and business ownerOperations and IR leadservice/transaction health, identity checks, clean re-hunt at 24h/7d/30d, closure recordreopen on new hash, persistence, tunnel, identity, or transaction evidence

Continuity rule: do not automatically isolate payment infrastructure, revoke all identities, rotate every certificate, or disable financial services. Preserve evidence, identify demonstrated exposure, and use the incident commander plus business owner for each disruptive step.

12

Detection Coverage and Validation Evidence

Validation state: STATIC REVIEW PASSED after local structure/safety, maintained-field, CQL heuristic, IOC provenance, and duplicate checks. This is not Falcon parsing or tenant-behavior evidence.

TechniqueCoverageQueriesEvidenceLimitation
T1566GapNo portable primary queryPlatform-native or tenant-specific telemetry requiredSee native hunts and H08 gap
T1016StaticQ02Static-only local reviewTenant parse, positive canary, and benign baseline absent
T1021.001GapNo portable primary queryPlatform-native or tenant-specific telemetry requiredSee native hunts and H08 gap
T1021.002GapNo portable primary queryPlatform-native or tenant-specific telemetry requiredSee native hunts and H08 gap
T1572GapNo portable primary queryPlatform-native or tenant-specific telemetry requiredSee native hunts and H08 gap
T1071.004StaticQ07Static-only local reviewTenant parse, positive canary, and benign baseline absent
T1562.001StaticQ03Static-only local reviewTenant parse, positive canary, and benign baseline absent
T1070.001StaticQ04Static-only local reviewTenant parse, positive canary, and benign baseline absent
T1053.005StaticQ05Static-only local reviewTenant parse, positive canary, and benign baseline absent
T1543.003StaticQ05Static-only local reviewTenant parse, positive canary, and benign baseline absent

Recorded evidence and gaps

  • Tenant execution evidence is absent; no query is described as parsed, tested, validated, or deployed.
  • The offline tenant-validation dry run records extraction and profile blockers only and does not contact Falcon.
  • H08 remains a gap for WebSocket SOCKS5 and cookie-gated HTTPS semantics.
  • Identity, RDP/SMB, cloud, CI/CD, Kubernetes, HSM, mTLS, and payment-transaction coverage requires platform-native schemas.
  • Next step: run Q03 and Q04 manually in the intended repository for one hour, confirm returned fields, then execute safe positive and representative benign tests before scheduling.
13

Hunt Summary Ticket

TITLE:        BREEZE COMET / UNC5669 financial-system intrusion hunt — v0.3 Draft
SEVERITY:     high — active, developing operations combine financial-system access with custom backdoors and defense evasion
SCOPE:        Falcon endpoint process/DNS telemetry; platform-native identity, network, cloud, Kubernetes, HSM, and payment logs where available
HYPOTHESIS:   H01 hash correlation; H02 reconnaissance; H03 Defender impairment; H04 log clearing; H05 persistence; H06 RMM/VPN inventory; H07 Java DNS; H08 tunnel gap
QUERIES RUN:  Q06 inventory; Q01/Q02/Q05/Q07 hunt; Q03/Q04 alert-candidate designs retained as hunt-only
DO FIRST:     Q03 and Q04 over 30 days, then same-host Q01/Q02/Q05/Q06/Q07 pivots
FINDINGS:
GAPS:         tenant parse/canary/baseline absent; encrypted tunnel, identity, cloud, Kubernetes, HSM, and payment schemas not mapped
ACTIONS:      SOC validates Q03/Q04 fields; Detection Engineering records positive/benign tests; service owners review CTRL01-CTRL08 pilots
OWNER:        SOC / Detection Engineering / Endpoint, Identity, Network, Platform, and Payment owners
VERSION:      v0.3 Draft · 2026-09-04 · STATIC REVIEW PASSED
14

Changelog

v0.3 Rich visual emphasis2026-09-04Added coordinated semantic color to Executive Summary lead-ins, threat metadata, Severity, and IOC counts. Detection logic, evidence, indicators, hardening, and validation claims are unchanged.
v0.2 Theme refresh2026-09-04Applied the deterministic threat-aware HuntPack palette. Detection logic, evidence, indicators, hardening, and validation claims are unchanged.
v0.1 Draft2026-09-01Initial BREEZE COMET pack with seven CQL queries, 22 provenance-bound indicators, eight reversible hardening designs, and a threat-specific containment workflow.
15

References

IDPublisherVersion/dateAccessedUseURL
S01Google Threat Intelligence Group / Mandiant2026-09-01 report2026-09-01T11:04:14ZThreat research / indicatorshttps://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil
S02Axur Research Teamcurrent cited edition2026-09-01T11:04:14ZThreat research / indicatorshttps://blog.axur.com/en-us/axur-reveals-plump-spider-modus-operandi-systemic-pix-fraud
S03Trend Micro Researchcurrent cited edition2026-09-01T11:04:14ZThreat research / indicatorshttps://www.trendmicro.com/en_us/research/26/e/vibe-hacking-two-ai-augmented-campaigns-target-government-and-financial-sectors-in-latin-america.html
S04Microsoft Learncurrent cited edition2026-09-01T11:04:14ZHardening authorityhttps://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/appcontrol
S05Microsoft Learncurrent cited edition2026-09-01T11:04:14ZHardening authorityhttps://learn.microsoft.com/en-ca/powershell/module/defender/set-mppreference?view=windowsserver2022-ps
S06CISAcurrent cited edition2026-09-01T11:04:14ZHardening authorityhttps://www.cisa.gov/resources-tools/resources/implementing-phishing-resistant-mfa
S07NISTcurrent cited edition2026-09-01T11:04:14ZHardening authorityhttps://csrc.nist.gov/pubs/sp/800/207/final