# New Cybercrime Groups Emerge to Target Brazil’s Financial Infrastructure Through Cloud Exploits and Payment System Attacks
A wave of sophisticated cybercrime campaigns has been identified targeting Brazil’s financial sector, with threat actors demonstrating an alarming level of expertise in cloud environments and the country’s increasingly dominant digital payment ecosystem. These campaigns mark a significant evolution in how financially motivated hackers approach Latin American financial institutions.
## Understanding the Threat Landscape
Two distinct criminal operations have recently come under the spotlight for their targeting of Brazilian banks, fintech companies, and digital asset platforms. Both groups have shown a remarkable understanding of the infrastructure that underpins Brazil’s digital economy, suggesting insider-level knowledge of how financial transactions are processed and secured.
The primary targets of these campaigns include the country’s widely adopted instant payment platform, digital currency custody systems, and the cloud infrastructure that major financial organizations rely on for day-to-day operations. By focusing on these high-value assets, the attackers aim to cause maximum financial damage in the shortest possible timeframe.
## Attack Methodology: Cloud-First Intrusions
What sets these threat actors apart from traditional banking fraud groups is their approach to gaining access to financial systems. Rather than relying on consumer-facing phishing or malware-laden email attachments, the attackers have developed custom techniques designed to exploit cloud environments directly.
One method involves using scripted tools to query cloud service metadata, which can expose temporary access credentials tied to organizational accounts. Once inside a cloud environment, the attackers systematically search for stored secrets — including those linked to cryptocurrency wallets and digital payment systems — and extract them for their own use.
The attackers have also shown a preference for building their own tooling rather than relying on publicly available frameworks. By writing custom scripts using native system tools, they reduce their exposure to security detection mechanisms that might flag downloaded or third-party utilities. This approach reflects a high degree of operational discipline and technical sophistication.
In observed incidents, the attackers deployed backdoor programs disguised as legitimate infrastructure binaries to maintain persistent access. They further expanded their foothold by compromising development pipelines and managed container environments, allowing them to push malicious code across the organization’s infrastructure with minimal friction.
## Custom Tooling and Automation Panels
A defining feature of these campaigns is the use of custom-built web dashboards that automate key stages of the attack lifecycle. These panels serve different purposes in the chain of operations:
– **Endpoint Scanning Tools:** Web-based interfaces designed to map out exposed services and APIs belonging to target organizations, categorizing them by industry — including fintech, banking, and cryptocurrency sectors — and identifying potential points of entry.
– **Email Reconnaissance Dashboards:** Interfaces that harvest data from compromised corporate email accounts, sorting messages into categories such as finance, administration, and regional focus, enabling the attackers to gather intelligence before executing their next move.
– **Bulk Transaction Panels:** Dedicated tools built to execute large-scale unauthorized payment transfers from compromised accounts, leveraging the speed and automation of the instant payment system to move funds rapidly before detection becomes possible.
Command-and-control infrastructure has also been found to include exposed panels displaying lists of compromised machines and exfiltrated data files from multiple Brazilian financial organizations.
## The Targeted Payment Ecosystem
Brazil’s shift toward digital payments has created an attractive landscape for cybercriminals. The country’s instant payment platform, which has become the most widely used payment method nationwide, processes enormous volumes of transactions daily. For attackers who can gain access to accounts tied to this system, the opportunity for illicit financial gain is substantial.
The attackers have been observed targeting the payment infrastructure at multiple levels — from individual user accounts to the backend systems that financial institutions use to process and route payments. Payment methods under threat include instant transfers, traditional bill-payment systems, and reserve transfer networks that form the backbone of the country’s financial operations.
Additionally, the attackers have shown interest in digital asset custody credentials. By stealing the keys that control cryptocurrency wallets held by financial institutions, the threat actors can potentially drain virtual currency reserves in a single operation — assets that are inherently difficult to trace or recover.
## A Second Wave: Cross-Regional Expansion
A separate criminal operation has been identified that shares some similarities with the first group but operates with its own distinct characteristics. This second group has been active since at least 2024 and has primarily focused on infiltrating the systems Brazilian financial organizations use to conduct payment transactions.
What makes this group particularly concerning is its willingness to exploit government websites as staging grounds for malware distribution. By compromising public-sector sites within Brazil, the attackers leverage the trust and reputation of government domains to carry out follow-up social engineering attacks against their financial targets.
Even more troubling is the group’s apparent interest in expanding beyond Brazil’s borders. Security researchers have observed attempts to replicate the same attack playbook in countries including Nigeria, Paraguay, Ghana, and Venezuela — targeting municipal and government websites in these regions as potential launchpads for future financial fraud campaigns.
## Why This Matters for the Global Financial Sector
The emergence of these groups signals a broader trend in cybercrime: the movement away from opportunistic, high-volume retail fraud toward targeted, infrastructure-level intrusions. Traditional banking malware typically cast a wide net, hoping to catch individual consumers or small businesses. The campaigns described here, however, represent a calculated effort to reach the core systems that move money at scale.
This shift is not limited to Brazil. Financial organizations worldwide that rely on cloud infrastructure, instant payment networks, and digital asset custody services should take note. The techniques demonstrated by these groups — cloud credential harvesting, pipeline compromise, and custom backdoor deployment — are not geographically bound and can be adapted to target financial institutions in any country.
The increasing connectivity of global payment systems means that a breach in one country’s financial infrastructure can have ripple effects far beyond its borders. As digital payment adoption continues to grow worldwide, the attack surface available to financially motivated threat actors expands correspondingly.
—
## Frequently Asked Questions (FAQ)
**Q: What is the instant payment system that is being targeted in Brazil?**
A: Brazil’s instant payment platform is a real-time electronic payment system that enables users to send and receive money instantly through smartphones or digital wallets. It has become the dominant payment method in the country due to its speed, low cost, and widespread adoption across businesses and consumers.
**Q: How do these threat actors gain initial access to financial organizations?**
A: The exact initial access vector has not been fully disclosed, but the attackers have demonstrated the ability to exploit cloud environments directly. Techniques include querying cloud metadata to harvest temporary credentials, searching for stored secrets in cloud credential managers, and compromising development pipelines to deploy malicious code across organizational infrastructure.
**Q: Why are Brazilian financial institutions specifically targeted?**
A: Brazil has one of the most advanced and rapidly growing digital payment ecosystems in the world. The widespread adoption of instant payments, combined with the growing use of digital asset custody services by financial institutions, creates a high-value target with significant potential for large-scale financial theft.
**Q: What types of financial assets are at risk in these attacks?**
A: The attacks target both traditional payment accounts tied to instant transfer systems and cryptocurrency wallets held by financial institutions. The theft of digital asset custody credentials is particularly concerning because cryptocurrency transactions can be difficult to reverse or trace.
**Q: Can similar attacks happen to financial institutions outside of Brazil?**
A: Yes. The techniques being used — cloud credential harvesting, infrastructure impersonation, and supply chain pipeline compromise — are applicable to any organization that relies on cloud services and digital payment infrastructure. Financial institutions globally should review their cloud security posture and payment system defenses.
**Q: How do the attackers avoid detection while operating inside cloud environments?**
A: The attackers use several stealth techniques, including disguising their backdoors as legitimate infrastructure binaries, using native system tools (like OpenSSL) instead of third-party libraries to avoid security alerts, and building custom tools that are less likely to match known threat signatures.
**Q: What role do compromised government websites play in these campaigns?**
A: In some observed cases, attackers have compromised Brazilian government websites to host malware and exploit the trust associated with government domains. They then use this trust to conduct social engineering attacks, making it more likely that targeted financial organizations will interact with malicious content.
**Q: Is there any indication that these groups are state-sponsored?**
A: Based on currently available information, these operations are characterized as financially motivated cybercrime groups rather than state-sponsored entities. Their primary objective appears to be monetary gain through direct theft of funds and digital assets.
—
## Conclusion
The targeting of Brazil’s financial infrastructure by two distinct cybercrime groups underscores a critical shift in the global threat landscape. Attackers are moving beyond traditional retail fraud and developing the technical capabilities to directly compromise the cloud systems, payment networks, and digital asset platforms that modern financial institutions depend on.
The sophistication of these campaigns — from custom-built cloud exploitation tools to automated attack dashboards and cross-border expansion strategies — demonstrates that financially motivated threat actors are evolving rapidly. Organizations around the world that operate payment systems, digital wallets, and cloud-based financial infrastructure must take note of these developments and strengthen their defensive postures accordingly.
As digital payments continue to grow in adoption globally, the lessons from Brazil’s experience serve as a warning: the financial sector must prioritize cloud security, credential protection, and infrastructure-level monitoring to stay ahead of adversaries who are increasingly targeting the systems that move money at scale.
Thank you for reading



