Google uncovers AI-assisted malware targeting Brazilian banks
Google disclosed BREEZE COMET, an AI-assisted malware campaign targeting Brazilian banks and payment processors. The group — tracked as UNC5669 — manipulates Pix, STR, and Boleto payment systems using stolen mTLS credentials. Custom tooling includes a Rust SOCKS5 tunneler, LDAP brute-forcer, and DNS tunnel backdoor. The group has successfully executed fraudulent transfers totaling tens of thousands USD across 2024-2025.
Financial institutions with RSFN network access must audit certificate storage, scan CI/CD for hardcoded credentials, and block unapproved RMM tools. The threat actors exploit AD environments, Kubernetes clusters, and JBoss servers. Infrastructure analysis suggests expansion into Latin America and Africa.
In this issue:
- BREEZE COMET malware: Brazilian bank fraud with LLM-generated recon scripts
- BigQuery Graph GA: native GQL, 100x faster undirected traversals, cross-cloud federation
- AWS Graviton5 R9g instances: DDR5-8800 memory, 5x larger L3 cache, 100 Gbps network
- NVIDIA Vera scheduler patches: 10Ki cycle SMT transition penalty fix, 7% GEMM improvement
Google Discloses BREEZE COMET Financial Malware Campaign
The Signal
Google Threat Intelligence Group disclosed BREEZE COMET (UNC5669), targeting Brazilian banks and payment processors with AI-assisted malware.
What Changed
- BREEZE COMET manipulates Pix, STR, and Boleto payment systems via compromised mTLS credentials and APIs.
- Custom malware suite includes COBALTSPIN (Rust SOCKS5 tunneler), REALBREEZE (LDAP brute-forcer), and MILDFROST (DNS tunnel backdoor).
- Threat actors use LLMs to generate reconnaissance scripts and credential validation tools.
- Compromised municipal websites in Brazil, Nigeria, Paraguay, Ghana, Venezuela host XWORM payloads.
- Group successfully executed fraudulent transfers totaling tens of thousands USD in 2024-2025.
Operational Impact
Financial institutions and payment processors with access to Brazil's RSFN network face direct exposure. Teams must audit mTLS certificate storage, CI/CD pipelines for hardcoded credentials, and SMB/RDP lateral movement paths. The group targets Active Directory environments, Kubernetes clusters, and JBoss AS servers. Organizations should immediately implement application control to block unapproved RMM tools and enforce 802.1X NAC at branch locations to prevent rogue hardware insertion.
Watch For
Infrastructure analysis suggests expansion beyond Brazil into Latin America and Africa. Monitor for .gov domain compromises used as trusted C2 endpoints and payload staging infrastructure.
BigQuery Graph reaches GA with native GQL
The Signal
Google Cloud's BigQuery Graph hit general availability with ISO Graph Query Language (GQL) support natively in the data warehouse.
What Changed
- GQL runs alongside SQL on BigQuery tables without ETL to separate graph databases.
- Query performance improved 2x overall, 100x for undirected traversals since preview.
- Federates across Iceberg tables in Databricks, AWS Glue, Snowflake without data movement. https://cloud.google.com/blog/products/data-analytics/bigquery-graph-connecting-data-and-ai-at-scale
- Inherits BigQuery row and column security; calls BigQuery ML functions in same query.
- New `CALL` statement and subquery support for composable graph patterns.
Operational Impact
Teams running separate graph databases for fraud detection or supply chain analysis can consolidate into BigQuery. Row-level security policies apply directly to graph traversals. Multi-hop queries for threat correlation or identity resolution now run where the data already lives. Cross-cloud federation means querying supplier relationships spanning AWS and GCP catalogs in a single traversal.
Watch For
Query performance will depend on graph topology and cardinality — test multi-hop patterns against your actual data. Agent skills for graph schema generation are rolling out soon but still maturing.
AWS Graviton5 R9g Instances Reach GA
The Signal AWS R9g and R9gd instances with Graviton5 processors are generally available with 25% faster compute.
What Changed
- Graviton5 delivers DDR5-8800 MT/s memory, up from 5600 MT/s in Graviton4
- 5x larger L3 cache and up to 3x packet processing performance vs R8g
- r9g.48xlarge and r9gd.48xlarge provide 100 Gbps network, 72 Gbps EBS bandwidth
- Instance Bandwidth Configuration adjusts EBS/VPC allocation by 25% for tuning
- Available in US East, US West (Oregon), and Europe (Frankfurt) https://aws.amazon.com/blogs/aws/amazon-ec2-r9g-and-r9gd-instances-powered-by-aws-graviton5-processors-are-now-generally-available
Operational Impact Teams running R8g instances can migrate to equivalent R9g sizes without code changes for immediate performance gains. The faster memory and doubled network bandwidth on larger instances benefit in-memory databases like Redis and Valkey, plus real-time analytics workloads. R9gd variants add local NVMe for workloads needing low-latency scratch storage.
Watch For Instance Bandwidth Configuration is new tuning surface for memory-heavy workloads with asymmetric network vs storage needs. Monitor whether DDR5-8800 delivers measurable latency improvements for your specific cache hit patterns.
NVIDIA Scheduler Patches Target Vera SMT Mode Transition Penalty
The Signal
NVIDIA submitted Linux kernel patches to optimize Olympus core SMT scheduling on Vera processors.
What Changed
- Olympus SMT has 10Ki cycle penalty transitioning from two-thread to single-thread mode.
- Patches add SD_ASYM_PACKING to prefer PE0 sibling, preventing performance-degrading mode transitions.
- Builds on Linux 7.3 commit 293f9611ae735 which improved NOHZ idle balancing for Vera.
- 88-thread single-precision GEMM benchmark improved from 9.4 to 10.1 TFLOP/s on two-socket Vera.
- Scheduler now selects highest-priority sibling within idle cores to minimize brief activations.
Operational Impact
Teams running HPC or AI workloads on NVIDIA Vera hardware will see more consistent SMT performance. The patches address a hardware-specific behavior where brief sibling wakeups degrade throughput even after the sibling idles. Prior work in 7.3 already boosted the same GEMM benchmark from 6.2 to 9.2 TFLOP/s; these patches add another 7% on top.
Watch For
Patches are under review on LKML. Merge timing depends on maintainer feedback and testing across other SMT architectures.
Quick Reads
- Google Threat Intelligence — Disclosed BREEZE COMET malware campaign targeting Brazilian banks with AI-assisted tools.
- BigQuery Graph — Reached GA with native GQL support, 2x faster performance, cross-cloud federation.
- AWS Graviton5 — R9g instances now GA with 25% faster compute, DDR5-8800 memory.
- NVIDIA Vera — Linux scheduler patches reduce SMT mode transition penalty, boost performance 7%.
Subscribe to Signal Field
Data & infrastructure news. Subscribers get new posts by email a day before they go live on the site.
Email signup is coming soon — in the meantime, follow the Signal Field RSS feed.