CrowdStrike has named a new Brazil-based threat group, Slim Spider, that has been raiding Brazilian financial firms for crypto custody secrets since March. The intrusions it describes blend cloud metadata theft with a precise understanding of Pix, the country’s instant payment rail.
Custom Bash scripts did the initial dirty work at the late-March intrusion, pulling temporary credentials from the cloud instance metadata service over socket connections. From there the group swept the credential manager for secrets and cloned extraction scripts with sed, homing in on credentials tied to digital assets.
With custody secrets exfiltrated, the attackers ran cast, a Foundry component built for Ethereum development, to map stolen private keys to wallet addresses. They signed transactions with OpenSSL inside Bash instead of third-party libraries, a choice CrowdStrike attributes to careful operational security. Implants that mimicked legitimate infrastructure binaries spread through a managed Kubernetes cluster, including one named “spi” after the system behind Pix, and malicious Azure DevOps pipelines extended the group’s reach.
An exposed command-and-control panel showed compromised hosts across several Brazil-based banks and fintechs, with archive files that were likely exfiltrated, CrowdStrike says. A Go backdoor called MikeDor adds credential harvesting and activity monitoring. The profile arrives as Google’s Threat Intelligence Group warns about Breeze Comet, another Portuguese-speaking crew that has abused Brazilian payment systems since 2024.
