Slim Spider Cybercrime Group Exploits Cloud Vulnerabilities to Steal Crypto Custody Credentials from Brazilian Financial Institution
A financially motivated threat group, Slim Spider, exploited cloud infrastructure vulnerabilities to steal cryptocurrency custody credentials from a Brazilian financial institution, leveraging custom scripts and cloud-native cryptographic tools. The attack targeted digital asset platforms and instant payment systems, highlighting escalating sophistication in cloud-based financial cybercrime.
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.
Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.
"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
*** END OF TRANSMISSION ***