Slim Spider Linked to Cloud Credential Theft Targeting Brazilian Financial Firms
Cybersecurity firm CrowdStrike says a previously unreported, financially motivated threat group has targeted Brazilian financial organizations with the apparent goal of stealing cryptocurrency custody...
Cybersecurity firm CrowdStrike says a previously unreported, financially motivated threat group has targeted Brazilian financial organizations with the apparent goal of stealing cryptocurrency custody credentials and accessing instant-payment accounts.
The group, tracked as Slim Spider, has been active since at least March 2026, according to the company. Researchers said the actor appears familiar with Brazil's financial ecosystem, including Pix instant payments, digital-asset services and cloud-hosted infrastructure.
Cloud-focused intrusion activity
In an intrusion observed in late March, Slim Spider allegedly used custom Bash scripts to collect temporary cloud credentials from instance metadata services. After gaining access to a victim's cloud environment, the attackers reportedly searched cloud secret-management systems for credentials associated with digital assets.
CrowdStrike said the operators modified scripts with standard command-line tools and used Foundry's cast utility to derive Ethereum wallet addresses from stolen private keys. The group also used OpenSSL for cryptographic operations within its scripts, an approach that may reduce reliance on external tooling and help blend activity into cloud environments.
The attackers then attempted to expand access to cloud container clusters and Azure DevOps environments. Malicious pipelines were reportedly used to deploy implants in managed Kubernetes clusters. One implant, called “spi,” appeared intended to resemble Brazil's Sistema de Pagamentos Instantâneos, the infrastructure behind Pix.
Panels and payment fraud
Investigators also identified web panels attributed to the group that support endpoint scanning, Microsoft 365 email reconnaissance and bulk Pix transfers. An exposed command-and-control interface reportedly showed compromised systems associated with Brazilian banks and fintech companies. CrowdStrike also linked Slim Spider to MikeDor, a Go-based backdoor designed to collect information and monitor users.
The report follows separate research on Breeze Comet, another Portuguese-speaking cybercrime group accused of compromising financial systems used for Pix, Boleto and Reserves Transfer System transactions. Researchers say that group has also abused compromised government websites to host malware and support social-engineering activity.
Both cases illustrate increased criminal interest in the cloud credentials, payment platforms and operational systems closest to high-value financial assets. Organizations operating payment and digital-asset services should review cloud identity permissions, secret-management access, DevOps pipeline controls and monitoring for unauthorized transaction activity.
