Select a theme from the list.
Insights

From our experts

Latest
Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformSlim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesUnpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemPasskey Reset Scams Turn Strong Authentication Into Cloud PersistenceFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development Platform
Security Insight

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps Pipelines

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps Pipelines
Photo by Josh Eleazar on Pexels

Researchers have identified Slim Spider, a financially motivated threat actor targeting Brazilian banks, cryptocurrency custody systems and instant-payment infrastructure. The group combines cloud credential theft, secret-store enumeration, Kubernetes access and malicious Azure DevOps pipelines to reach assets that can be converted directly into money.

A newly documented cybercrime group is showing how financial attacks are moving beyond customer accounts and into the cloud infrastructure that controls institutional payments and cryptocurrency. Tracked as Slim Spider, the Brazil-based actor has demonstrated detailed knowledge of banking technology, the Pix instant-payment ecosystem and digital-asset custody operations.

Targeting credentials closest to the money

In an intrusion observed at a Brazilian financial institution, Slim Spider used custom Bash scripts to query cloud instance metadata and obtain temporary credentials. The attackers then searched the organization's cloud credential manager for secrets associated with valuable financial systems and digital assets.

After stealing cryptocurrency custody material, the group reportedly used an Ethereum development tool to determine the wallet address connected to a compromised private key. It also implemented cryptographic signing through OpenSSL inside its own scripts, reducing its reliance on external libraries that could create additional detection opportunities.

The operation extended into managed container infrastructure. Slim Spider established access to cloud container-service nodes, deployed backdoors with names resembling legitimate infrastructure components and pivoted into Azure DevOps. Compromised development credentials were apparently used to execute malicious pipelines that distributed implants across a Kubernetes cluster.

Cloud administration becomes a financial control

This campaign matters because it treats DevOps systems, cloud metadata services and secret managers as parts of the payment environment. An attacker who controls a deployment pipeline may be able to place code near transaction-processing services without attacking a traditional banking application directly.

In my view, financial institutions must stop treating cloud credentials as ordinary IT secrets. Credentials capable of reaching wallets, signing services or payment infrastructure should be protected as financial instruments, with strict separation of duties and continuous monitoring.

Reducing the attack surface

  • Limit workload access to instance metadata and require hardened metadata-service configurations.
  • Use short-lived, narrowly scoped identities instead of reusable cloud credentials.
  • Prevent DevOps service accounts from directly retrieving production custody secrets.
  • Require approval and cryptographic validation for production pipeline changes.
  • Monitor secret-store enumeration, unusual pipeline execution and unexpected container deployments.
  • Keep signing keys in hardware-backed systems that do not expose private material to workloads.

Slim Spider represents a shift from high-volume consumer fraud toward direct compromise of financial infrastructure. I believe this model will attract imitators because cloud systems can provide a quiet route to assets with immediate monetary value. Defenders should therefore map every technical identity and automation pipeline that can influence a transaction, not merely the applications visible to customers.

Talk to our team →

Latest

Slim Spider Moves Bank Robbery Into Cloud Secrets and DevOps PipelinesSep 10, 2026Unpatchable Earbuds Expose Bluetooth's Forgotten Security ProblemSep 10, 2026Passkey Reset Scams Turn Strong Authentication Into Cloud PersistenceSep 10, 2026Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path