HackMyIP
← Back to News
2026-09-08 The Hacker News

Slim Spider: Brazilian Hackers Steal Crypto Secrets via Cloud Credential Theft

APTCloud SecurityThreat Intel

CrowdStrike has uncovered a previously undocumented, financially motivated threat actor dubbed "Slim Spider," actively targeting Brazilian financial institutions since at least March 2026 to steal cryptocurrency custody secrets and hijack Pix instant payment accounts. The adversary demonstrates unusually deep operational knowledge of Brazil's financial ecosystem, including the Pix instant payment service, digital asset platforms, and the cloud environments underpinning major banks and fintechs.

In a multi-stage intrusion observed at a Brazil-based financial institution, Slim Spider deployed custom Bash scripts that queried cloud instance metadata over socket connections to harvest temporary cloud credentials. Once inside the environment, the group enumerated every secret stored in the cloud credential manager and used the "sed" command to clone and modify secret-extracting scripts. Following the exfiltration of digital asset custody secrets, Slim Spider invoked Cast, a component of the Foundry Ethereum developer toolkit, to derive wallet addresses from stolen private keys—then implemented cloud-native cryptographic signing directly via OpenSSL to avoid third-party libraries that could trigger detection. The group's deliberate choice to handle signing natively in Bash reflects sophisticated operational security awareness. Organizations can audit their own exposure with a password checker to identify weak or reused credentials that fuel these kinds of cloud-native attacks.

Slim Spider then established access to nodes running in a cloud container service cluster and deployed backdoors mimicking legitimate infrastructure binaries. Using compromised credentials, the threat actor pivoted to Azure DevOps, executing malicious pipelines that spread additional implants across a managed Kubernetes cluster. One implant was deliberately named "spi" to impersonate the Sistema de Pagamentos Instantâneos (SPI), the central infrastructure that processes Pix payments in Brazil. The group's supporting toolkit includes web-based panels such as NEXUS // Scanner, which uses Ollama to classify and rank scanned API endpoints by category, alongside Entra ID email reconnaissance and bulk Pix transaction panels.

The campaign underscores how cloud-first threat actors are weaponizing native tooling—metadata services, CI/CD pipelines, and Kubernetes—to blend in with legitimate operations. Defenders should harden IMDS access, enforce least-privilege secrets management, monitor DevOps pipeline activity, and audit certificate hygiene using an SSL/TLS checker to ensure encrypted channels aren't silently compromised. With Slim Spider combining AI-assisted reconnaissance, cloud-native tradecraft, and niche knowledge of Brazilian fintech infrastructure, financial institutions across Latin America should treat this cluster as a persistent, high-priority threat.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →Browser Fingerprint →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →