The emergence of Slim Spider, a previously undocumented financially motivated threat actor targeting Brazilian financial institutions, highlights an important shift in cybercrime: attackers are increasingly moving beyond retail banking fraud and directly targeting the cloud infrastructure and credentials that control high-value financial assets. CrowdStrike has tracked Slim Spider activity since at least March 2026 and says the group demonstrates deep knowledge of Brazil’s financial ecosystem, including Pix, digital asset platforms and cloud environments used by financial institutions. In one observed intrusion against a Brazil-based financial organization, the attackers targeted both cryptocurrency custody assets and instant-payment accounts, using custom tooling to steal temporary cloud credentials, enumerate secrets and ultimately obtain access to sensitive digital asset custody information.
What makes the attack particularly significant is the way Slim Spider approached cloud credentials. The attackers reportedly developed custom Bash scripts that queried cloud instance metadata and extracted temporary credentials through socket connections. After entering the organization’s cloud environment, they enumerated secrets stored in the credential manager and modified scripts specifically to identify credentials associated with digital financial assets. This is a valuable reminder that metadata services, instance identities and cloud-native credential stores are now part of the financial attack surface. Attackers do not necessarily need to steal a long-lived administrator password if they can obtain temporary credentials that already inherit the permissions required to access sensitive infrastructure.
Temporary credentials are often considered safer because they expire automatically, and in general they are. But expiry does not help if an attacker steals the credential while it is valid and immediately uses it to access secrets, APIs or workloads. The security value of short-lived credentials depends heavily on how narrowly they are scoped, where they can be used and whether abnormal use can be detected quickly. A temporary credential capable of reading a secret manager containing cryptocurrency custody keys may remain valid for only a short period, but that period can still be more than sufficient for an attacker to extract the most valuable information in the environment.
The custody-secret theft is the most serious element of the intrusion. CrowdStrike says Slim Spider extracted digital asset custody secrets and then used `cast`, part of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key. The attackers also implemented cryptographic signing directly through OpenSSL inside their Bash tooling rather than depending on third-party libraries. This indicates that the operation was not simply collecting secrets opportunistically. The attackers understood what the credentials controlled, how they related to digital assets and how they could be used within cryptocurrency transaction workflows.
This distinction matters because crypto custody infrastructure should be treated less like an ordinary application and more like a financial control system. A private key or custody credential may provide authority over assets directly. If attackers steal database credentials, they may need additional steps to turn the access into money. If they steal signing material controlling a wallet, the path from compromise to financial loss can be dramatically shorter. That makes custody secrets among the highest-value credentials in any financial environment.
Slim Spider also appears to understand the broader infrastructure around those assets. After compromising cloud credentials, the attackers moved into nodes running in a cloud container-service cluster and deployed implants designed to resemble legitimate infrastructure binaries. They then pivoted into Azure DevOps, likely using compromised credentials, and executed malicious pipelines that deployed additional backdoors across a managed Kubernetes cluster. One implant was named `spi`, apparently to imitate Sistema de Pagamentos Instantâneos, the infrastructure associated with Pix payments in Brazil.
That use of DevOps pipelines is particularly concerning because CI/CD systems are another concentration point for trust. A compromised pipeline can deploy code across many workloads through mechanisms administrators already expect to perform automated changes. Malicious activity can therefore arrive through the same deployment paths used by legitimate engineering teams. Defenders need to monitor not just whether a pipeline executed successfully, but who modified it, which credentials initiated it, whether the resulting images or scripts were expected and whether deployments correspond with an approved change.
The Kubernetes component adds another security layer. Container environments often contain service accounts, secrets, mounted credentials and network connectivity between applications. Once attackers reach a cluster, they can potentially enumerate workloads, secrets and service identities in much the same way they would explore users and credentials in a traditional Windows domain. Organizations should therefore treat Kubernetes API access, service-account token usage and secret retrieval as high-value security telemetry rather than ordinary infrastructure noise.
Slim Spider’s tooling also shows a high degree of operational specialization. CrowdStrike identified several web-based panels used to automate different phases of the operation. NEXUS // Scanner categorizes exposed API endpoints into areas such as banking, fintech, payments and cryptocurrency and ranks them based on availability and authentication requirements. Another panel searches compromised Microsoft 365 mailboxes and groups them according to categories such as finance, administration and Brazil, while a separate Pix panel is designed to execute bulk unauthorized instant-payment transfers from compromised accounts.
These tools reveal something important about the evolution of financially motivated threat actors. The objective is no longer simply to compromise systems. The attackers are building workflow automation around the business logic of financial institutions. They want to understand which systems process payments, which mailboxes belong to finance teams, which APIs control transactions and which secrets provide access to digital assets. In effect, they are building their own attacker-side financial operations platform.
That operational knowledge is what makes the threat particularly dangerous. Security teams sometimes focus heavily on malware sophistication while underestimating the value of business-process knowledge. An attacker does not need exceptionally advanced malware if they understand exactly which system initiates a Pix transfer, which credential signs a crypto transaction or which DevOps pipeline deploys the relevant application. Knowledge of the organization’s transaction architecture can be more valuable than a technically complex exploit.
The use of compromised Microsoft 365 mailboxes for reconnaissance reinforces the same point. Email remains one of the richest sources of internal business intelligence because it reveals vendor relationships, payment workflows, escalation procedures, organizational roles and internal terminology. Slim Spider’s panel reportedly categorizes compromised mailboxes according to financial relevance, which suggests the attackers are prioritizing access based on the victim’s business role rather than treating every account equally.
For defenders, this means mailbox compromise should not be evaluated solely in terms of email exposure. A finance mailbox can help attackers understand transaction approvals, identify cloud systems, discover vendor contacts and determine which employees control sensitive financial workflows. Identity monitoring for Microsoft 365 should therefore include abnormal mailbox searches, mass access, suspicious token use and sign-ins from unfamiliar infrastructure, particularly for finance and administrative personnel.
Another important lesson is the use of legitimate tools. `sed`, OpenSSL, Foundry’s `cast`, Bash, Azure DevOps and Kubernetes are all legitimate technologies. None is malicious by itself. Slim Spider’s tradecraft demonstrates once again that modern attackers frequently prefer trusted tooling because it reduces the amount of custom malware they need to introduce. Detection therefore has to focus on context and behavior rather than simply searching for unknown binaries.
For example, OpenSSL performing cryptographic operations is normal in many environments. OpenSSL being invoked unexpectedly by a newly modified Bash script immediately after secret-manager enumeration may be highly suspicious. Similarly, `cast` may be perfectly legitimate on a blockchain development workstation but unusual on a financial production server that has never previously interacted with Ethereum tooling. Baselines matter because the same binary can be completely benign in one context and an excellent attack signal in another.
The attack also reinforces the need to separate secret discovery from secret usage. Organizations frequently protect secret managers strongly but assume that any workload able to retrieve a secret is automatically trusted to use it. A stronger architecture should consider which workload retrieves the secret, from which identity, for what purpose and whether the request matches normal behavior. High-value custody keys and signing secrets should ideally require additional policy boundaries, hardware-backed protection or dedicated key-management infrastructure that does not simply return raw key material to arbitrary cloud workloads.
Hardware Security Modules can be particularly valuable in this context because the private key does not need to leave the secure hardware at all. Applications can request a cryptographic operation without receiving the underlying key. This reduces the value of compromising a secret manager because the attacker cannot simply extract reusable custody material. The security model shifts from protecting a retrievable secret to controlling which operations can be performed with a non-exportable key.
Organizations should also enforce strict separation between cloud infrastructure used for general applications and systems controlling digital asset custody. A workload capable of serving public APIs should not automatically inherit access to wallet-signing credentials. Similarly, compromise of a CI/CD pipeline should not provide direct authority to deploy into custody infrastructure without independent controls. Financial asset systems deserve their own security boundary, even if doing so creates some operational inconvenience.
Cloud metadata protections are equally important. Workloads should use IMDSv2 or equivalent hardened metadata mechanisms, restrict unnecessary access to instance metadata and apply network controls preventing untrusted processes or containers from querying metadata services. Permissions attached to instance roles should follow least privilege so that theft of one temporary credential does not expose every secret available in the cloud account.
Secret-manager access should also be monitored aggressively. Bulk enumeration of secrets, access to secret names never previously requested by a workload or retrieval from a new instance should trigger alerts. Slim Spider explicitly enumerated credential stores looking for financially valuable material, which creates a behavior defenders can hunt for even when the attacker is using valid temporary credentials.
The incident also demonstrates why financial organizations need to monitor transaction behavior independently of infrastructure authentication. If attackers eventually gain valid credentials for Pix or cryptocurrency systems, the transaction may technically appear authorized. Fraud detection therefore needs to consider amount, destination, frequency, timing and historical behavior rather than assuming that possession of a valid credential means the transaction is legitimate.
CrowdStrike also found an exposed Slim Spider command-and-control panel showing multiple compromised systems belonging to Brazilian banks and fintech organizations, suggesting that the group’s activity extends beyond a single financial institution. While public reporting does not establish the full victim count or financial losses, the evidence indicates a focused campaign targeting the financial ecosystem rather than an isolated intrusion.
Slim Spider’s emergence also coincides with activity from Breeze Comet, another financially motivated group targeting Brazilian payment infrastructure such as Pix, Boleto and the Reserves Transfer System. Google and Mandiant have observed Breeze Comet manipulating financial applications to initiate fraudulent payments, and some attacks have resulted in hundreds of unauthorized transactions. The presence of multiple criminal groups targeting the same payment ecosystem suggests that success in one campaign is likely encouraging further specialization.
This is an important strategic shift. Latin American cybercrime has historically been associated heavily with retail banking malware, credential theft and fraud against individual customers. Groups such as Slim Spider and Breeze Comet are moving upstream toward financial institutions themselves. Instead of stealing one consumer’s credentials, they are targeting the infrastructure that processes thousands or millions of transactions.
That change has serious implications for financial cybersecurity. The attacker’s most valuable target may no longer be the customer account. It may be the cloud identity that can retrieve the custody secret. Or the pipeline that can deploy code into the payment cluster. Or the service account authorized to initiate a Pix transfer.
The deeper lesson from Slim Spider is that modern financial assets increasingly depend on layers of cloud identity, DevOps automation and cryptographic infrastructure. Those layers are now part of the vault. Protecting the cryptocurrency wallet while leaving the cloud credential that unlocks its custody secrets exposed is rather like installing a better safe and leaving the combination in the deployment pipeline. Attackers have noticed.

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
Source: Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution via The Hacker News — published 08 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.