hacker-news · Crawled Sep 8, 2026
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
1 IoCs
Read original article ↗
AI Summary
Slim Spider is a financially motivated threat actor targeting Brazilian financial institutions since at least March 2026. The group conducts multi-stage intrusions into cloud environments to steal cryptocurrency custody secrets and access instant payment systems like Pix. They use custom Bash scripts to extract cloud credentials, implement cloud-native cryptographic signing via OpenSSL, and deploy backdoors such as MikeDor. Slim Spider also leverages malicious DevOps pipelines and maintains web-based panels for automating attacks, including endpoint scanning, email reconnaissance, and unauthorized Pix transactions.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | spi | Details → |