By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Slim Spider Targets Brazilian Banks for Crypto Custody Data

A financially motivated threat actor, identified as Slim Spider, has been actively targeting Brazilian financial institutions since at least March 2026, with a focus on stealing cryptocurrency custody secrets. Cybersecurity firm CrowdStrike is monitoring this activity cluster, which is believed to be based in Brazil. Slim Spider exhibits a sophisticated understanding of Brazil's financial infrastructure, including its instant payment system, Pix. The group's primary objective appears to be the exfiltration of sensitive data related to cryptocurrency holdings and custody services offered by these institutions.
CrowdStrike's analysis indicates that Slim Spider employs a range of tactics, techniques, and procedures (TTPs) to achieve its objectives. While specific details regarding the initial access vectors and malware used are still under investigation, the threat actor's operational knowledge suggests a well-resourced and determined entity. The group's focus on cryptocurrency custody data highlights a growing trend in cybercrime, where attackers are increasingly targeting digital assets and the infrastructure that secures them. This poses a significant risk to both financial institutions and their customers, potentially leading to substantial financial losses and reputational damage.
The emergence of Slim Spider underscores the evolving threat landscape in the financial sector, particularly in regions with rapidly growing digital payment and cryptocurrency adoption. Brazil's instant payment system, Pix, launched in November 2020, has seen widespread adoption, making it a critical component of the country's financial ecosystem. Threat actors like Slim Spider are likely leveraging the interconnectedness and increasing reliance on such digital platforms to facilitate their attacks. The group's ability to operate undetected for an extended period, since March 2026, suggests a high level of stealth and evasion capabilities.
CrowdStrike has not yet attributed Slim Spider to any specific nation-state or known cybercriminal syndicate, but its focus on financial gain and its operational sophistication point towards a professional, financially driven operation. The firm continues to gather intelligence on the group's activities and is working with affected institutions to enhance their defenses. The ongoing investigation aims to uncover the full scope of Slim Spider's operations, including the specific types of cryptocurrency custody information being targeted and the potential impact on the broader Brazilian financial market. The threat actor's deep knowledge of local financial systems is a key concern for cybersecurity professionals operating in the region.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.