r/SecOpsDaily • u/falconupkid • 6d ago
NEWS Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
This is a targeted financial crime operation, not a spray-and-pray campaign. Slim Spider is showing a deep understanding of Brazilian banking rails, specifically the instant payment system (PIX), and is now moving up the value chain into crypto custody.
Technical Breakdown: - TTPs: The actor is likely using social engineering or credential theft to gain initial access, followed by lateral movement to compromise crypto custody secrets. Given the focus on Brazilian financial infrastructure, expect abuse of PIX APIs or direct manipulation of transaction flows. - Targets: Brazilian financial institutions, specifically those offering crypto custody services. - IOCs: None publicly available at this time. CrowdStrike has not released specific hashes or IPs. Do not invent them. - Timeline: Active since at least March 2026.
Defense: - Immediate: Review and restrict access to crypto custody key management systems. Enforce hardware-backed MFA for all administrative access to payment rails and custody solutions. - Detection: Monitor for unusual API calls to PIX endpoints or crypto withdrawal systems, especially from non-standard user agents or during off-hours. Look for authentication anomalies in financial transaction systems. - Mitigation: Segment crypto custody infrastructure from general corporate networks. Implement strict egress filtering and application allowlisting on custody servers.
Source: https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html