Incident
Published 2026-09-08
Verified 2026-09-19

Slim Spider: Brazil e-crime cluster steals crypto custody secrets and Pix-linked cloud creds

CrowdStrike (covered by The Hacker News, 8 September 2026) tracks Slim Spider, a Brazil-based e-crime cluster active against Brazilian financial institutions since at least March 2026. In a late-March 2026 multi-stage intrusion at a Brazilian financial institution, the actor targeted crypto custody assets and Pix instant-payment infrastructure: custom Bash scripts queried cloud instance metadata for temporary credentials, enumerated secrets in the cloud credential manager, used Foundry cast to derive an Ethereum wallet address from a stolen private key, and implemented cloud-native signing via OpenSSL. The actor also pivoted to Azure DevOps to run malicious pipelines that deployed implants across a managed Kubernetes cluster, including backdoors mimicking legitimate infrastructure binaries (e.g. "spi" impersonating Sistema de Pagamentos Instantâneos). Primary: CrowdStrike adversary page; wire: The Hacker News.

Exploited in Australia?
unknown

Primary: CrowdStrike — Slim Spider adversary page · Vendor: The Hacker News (8 Sep 2026) · The Hacker News — Slim Spider / Brazil FI (8 Sep 2026)

breaches cloud identity