IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE29 IOCs

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

GT
Google Threat Intelligence (GTIG / Mandiant)
Published September 1, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYUNC5669INFRASTRUCTUREhttp://gcm.setelagoas…https://minacu.go.gov…http://suporte.ourinh…CAPABILITYChiselImpacketMETA StealerVICTIMunknown
Adversary(1)
Infrastructure(6)
Capability(4)
Victim

Indicators of Compromise

Indicators of Compromise29

TypeIndicatorConfidenceScoreFirst Seen
URLhttp://gcm.setelagoas.mg.gov.br/files/ti.zip
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://minacu.go.gov.br/ComprovantePDF.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttp://suporte.ourinhos.sp.gov.br:443/files/s.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256c0db6ddd6222d02ad7490399d33c61ded0076f0037409dc8498924458646d78a
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA25651fdd83b3737add7f3832bd0ad0b56863c0a8f7cf9bcc16fd787d1ae4b403ce6
botnetfile-hashintel-blog
High
85
Sep 2, 26
URLhttps://jmcov.gov.py/cxv.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256f139b4ca15feffb7a6633ec1a431c5c604b397576b56b5c863ae8fe4fa14db4f
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttp://gcm.setelagoas.mg.gov.br/files/notepadd.exe
africaai-assisted malwarebanking software
Medium
45
Sep 2, 26
URLhttp://suporte.ourinhos.sp.gov.br/files/s.zip
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://cmgovernadorluizrocha.ma.gov.br/Comprovantepdf.exe
exfiltrationintel-blogmalware
High
58
Oct 9, 26
SHA256de4e533c9062c62b3ba3a5d88eff111156075f2c92d243737edeead6481a9fd5
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA256d2aa40cc53b40c6e76ac0677c4a54387b3f27ee94c85d9b2c3a3d66aeef92a66
aptbotnetespionage
High
85
Sep 2, 26
URLhttps://tisup.camaratunapolis.sc.gov.br/SoftEther.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://sit.baer.gob.ve/r.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
Domaindontpad.com
exfiltrationindicatorintel-blog
Low
32
Sep 1, 26
SHA2566d4012e0dd3b56a3e52857734fa0d582cdf3c56f0e5decc8005c882d1d1c6ceb
file-hashintel-blogmalware
Medium
53
Oct 9, 26
URLhttps://www.mrtb.gov.ng/apps/attvpn.vip
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://servicos.salto.sp.gov.br/j.jar
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://suporte.camaratunapolis.sc.gov.br/ti/attvpn.zip
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://conseg.ssp.go.gov.br/ComprovanteBBpix.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttp://suporte.ourinhos.sp.gov.br/files/a.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://suporte.camaratunapolis.sc.gov.br/ti/1.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttp://gcm.setelagoas.mg.gov.br/files/tes.exe
africaai-assisted malwarebanking software
Medium
45
Sep 2, 26
URLhttp://credeb.gov.gn/r.zip
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256447e3a131e62bd33b1297739a7b959a92358a97f58554469044636a3c4f244e8
file-hashintel-blogmalware
Medium
53
Oct 9, 26
SHA2562214907e696bad85bde1d90c943ef66e413d7a5c6d7596ced25b74441200439a
file-hashindicatorintel-blog
Medium
55
Sep 2, 26
URLhttps://conseg.ssp.go.gov.br/COAF-POLICIAFEDERAL.exe
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttps://procon.go.gov.br/ComprovantePDF.exe
exfiltrationintel-blogmalware
High
58
Oct 9, 26
SHA2563b22605244dbace8f0c07c2c599f88c4b831bb07e9998b869a5da2759d27ceec
aptbotnetespionage
High
85
Sep 2, 26

IOC Relationship Graph

IOC Relationship Graph29 total IOCs
URLSHA256Domain
URL19SHA2569Domain1Actors1Malware4REPORTFinancially Motivated ThreUNC5669ChiselImpacketMETA StealerXWorm
scroll to zoom · drag to pan · click IOC to open