Brazilian Threat Actor Slim Spider Targets Financial Institutions for Cryptocurrency Assets
A financially motivated threat actor known as Slim Spider has been linked to attacks targeting Brazilian financial institutions since at least March 2026. The group, tracked by cybersecurity company CrowdStrike, demonstrates deep operational knowledge of Brazilian financial infrastructure.
Slip Spider has been observed orchestrating multi-stage intrusions, focusing on cryptocurrency assets and instant payment accounts. They developed custom Bash scripts to steal temporary cloud credentials over socket connections, then cloned and modified secret-extracting scripts to access digital asset custody secrets.
The threat actor invoked Cast, a component of the Foundry Ethereum developer toolkit, to derive the Ethereum wallet address associated with a stolen private key. Slim Spider has also been linked to various web-based panels, including NEXUS // Scanner, Painel de Emails Entra ID, and Painel Pix.