Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
Executive Summary
CrowdStrike has identified a new financially motivated threat actor, Slim Spider, targeting Brazilian financial institutions since March 2026. The group has stolen crypto‑custody secrets and demonstrated deep knowledge of Brazil’s instant‑payment infrastructure, marking a broader cluster of attacks on the country’s banking sector.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-08T16:20:23+00:00 - Category: threat-intel
Original Description: A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
"Through pride we are ever deceiving ourselves. But deep down below the surface of the average conscience a still, small voice says to us, Something is out of tune."
— Carl Jung