Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
AI-summarised brief · reviewed before publication
CrowdStrike has identified a financially motivated threat group, dubbed Slim Spider, conducting sophisticated attacks on Brazilian financial institutions since March 2026. The actors leveraged deep knowledge of Brazil’s instant‑payment system Pix, digital‑asset platforms, and cloud environments to infiltrate a major bank’s cloud infrastructure. Using custom Bash scripts, they harvested temporary cloud credentials, enumerated secrets in the cloud credential manager, and exfiltrated cryptocurrency custody keys. The group then employed the Foundry Ethereum toolkit’s “cast” utility and OpenSSL to derive wallet addresses and sign transactions without third‑party libraries. Further steps included deploying backdoors disguised as legitimate binaries, compromising Azure DevOps pipelines, and spreading implants across a Kubernetes cluster, including a “spi” implant mimicking the Pix infrastructure. An exposed C2 panel revealed compromised hosts across multiple banks, and the Go‑based backdoor MikeDor was also used to harvest data.
💡 Why It Matters
- · By stealing custody credentials, Slim Spider can directly authorize crypto withdrawals, turning cloud misconfigurations into immediate monetary loss for banks and their customers.