A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.
thehackernews.com
Publisher
Sep 8, 2026 at 4:20 PM UTC · 4 分で読める
Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.
"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities' cloud environments," CrowdStrike said.
Slim Spider has been observed orchestrating a multi-stage intrusion at a Brazil-based financial institution in late March 2026, setting its sights on the entity's cryptocurrency assets and instant payment accounts.
As part of the attack, the e-crime group is said to have developed custom Bash scripts that query the cloud instance metadata to steal temporary cloud credentials over socket connections.
Upon establishing access to the organization's cloud environment, the threat actor enumerated all available secrets stored in the cloud credential manager and used the "sed" command to clone and modify secret-extracting scripts. The approach specifically focuses on credentials tied to digital financial assets.
Market Context
Ethereum
ETH
$2,493
-0.07% (24H)
Market Cap
$303.7B
Circulating Supply
122.0M ETH
24H Volume
$11.8B
24H High
$2,507
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
