Breaking
Cyber CrimeDeveloping Story

Slim Spider Targets Crypto Custody in Brazil

CrowdStrike uncovers Brazil-based threat actor Slim Spider stealing cloud credentials to access cryptocurrency custody secrets.

··1 hour ago·4 min read
landscape photography of mountains
Photo by Shot by Cerqueira on Unsplash

A new threat actor with a sharp focus on financial infrastructure has been tying Brazilian institutions in knots since March 2026, according to cybersecurity firm CrowdStrike. Dubbed Slim Spider, this Brazil-based group is not just another retail fraud crew; it's going after the cloud environments where digital assets live, aiming for custody secrets that control cryptocurrency wallets.

Deep Knowledge of Brazilian Finance

CrowdStrike is tracking the activity cluster under the name Slim Spider and reports that the adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities' cloud environments.

In late March 2026, Slim Spider orchestrated a multi-stage intrusion at a Brazil-based financial institution, setting its sights on the entity's cryptocurrency assets and instant payment accounts. The attack was notable for its technical sophistication and the attackers' apparent comfort with cloud-native tools.

Custom Bash Scripts for Cloud Credentials

The e-crime group developed custom Bash scripts that query the cloud instance metadata to steal temporary cloud credentials over socket connections. This approach allowed them to gain a foothold in the organization's cloud environment without relying on noisy third-party tools.

Once inside, the threat actor enumerated all available secrets stored in the cloud credential manager, using the 'sed' command to clone and modify secret-extracting scripts. The focus was on credentials tied to digital financial assets, showing a clear understanding of where the most valuable data resides.

Bypassing Detection with OpenSSL

In a move that highlights their operational security awareness, Slim Spider avoided third-party libraries that could introduce detection risk. Instead, they implemented cloud-native cryptographic signing directly via OpenSSL within their Bash scripts. This deliberate choice reflected a nuanced understanding of cloud environments and a desire to stay under the radar.

The attackers then invoked cast, a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key. This step was crucial for confirming the value of the exfiltrated secrets and planning subsequent theft.

Blending In and Pivoting to DevOps

Slim Spider moved to establish access to nodes running in a cloud container service cluster while deploying backdoors that mimicked infrastructure-related binaries. This blending with legitimate tooling helped them fly under the radar.

They then pivoted to Azure DevOps, likely using compromised credentials, to run malicious pipelines that deployed additional implants across a managed Kubernetes cluster. One implant was named 'spi,' a deliberate attempt to impersonate Sistema de Pagamentos Instantâneos (SPI), the central digital infrastructure that processes Pix payments in Brazil.

Three Panels for Attack Automation

CrowdStrike linked Slim Spider to various web-based panels that automate different stages of the attack chain:

  • NEXUS // Scanner: an API endpoint-scanning panel that uses Ollama to sort endpoints into 16 categories, such as fintech, banking, payment, and cryptocurrency, and ranks them based on availability and authentication options.
  • Painel de Emails Entra ID: an email reconnaissance panel that searches compromised Microsoft 365 mailboxes, categorizing them into finance, admin, and Brazil groups.
  • Painel Pix: a transaction panel designed to execute bulk unauthorized Pix transfers from compromised accounts.

These panels show a high level of organization and intent to scale operations beyond a single intrusion.

Exposed C2 Panel Reveals Scope

CrowdStrike said it discovered an exposed command-and-control (C2) panel connected to the threat actor that displayed several compromised hosts from several Brazil-based banks and fintech organizations. The panel likely exfiltrated archive files, indicating the group's broad reach.

According to the cybersecurity vendor's adversary profile, another key tool in Slim Spider's arsenal is MikeDor, a Go-based backdoor capable of harvesting sensitive information and monitoring user activities. This backdoor has been seen in the wild, adding to the group's technical repertoire.

Why Slim Spider Matters

“Slim Spider's knowledge of the cloud attack surface allows them to target credentials associated with an organization's valuable digital currency assets, including custody credentials that control cryptocurrency wallets,” CrowdStrike said. “Access to such assets can result in devastating financial loss for victims.”

— CrowdStrike, cybersecurity firm

The threat actor's focus on cloud infrastructure and financial assets highlights a growing trend among e-crime groups. As more financial institutions move to cloud-based systems, the attack surface expands, and criminals are following. This could mean that other regions with similar payment infrastructures may become targets, as demonstrated by Breeze Comet's expansion to other countries.

The emergence of Slim Spider and Breeze Comet shows that Latin American cybercrime is shifting from retail fraud to direct intrusions into core financial systems. For organizations, this suggests a need to prioritize cloud security and protect credentials that control high-value assets. The stakes are high, and the attackers are only getting more sophisticated.

#slim-spider#crowdstrike#brazil#cloud-security#cryptocurrency#credential-theft

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories