Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
What Happened – An undocumented financially‑motivated threat group, tracked by CrowdStrike as “Slim Spider,” has been compromising Brazilian banks and exfiltrating private keys and other custody‑related credentials used to manage cryptocurrency assets. The campaign has been active since at least March 2026 and shows intimate knowledge of the country’s instant‑payment infrastructure.
Why It Matters for Trust & Control Assurance
- The incident exemplifies a failure to enforce strong identity‑and‑access controls over privileged crypto‑custody accounts – a core control that continuous‑monitoring programs are built to protect and evidence.
- Demonstrates the need for real‑time credential‑use analytics and audit‑ready logs that can prove due‑diligence during regulator or partner reviews.
- Highlights how a single compromised credential can expose high‑value assets, underscoring the importance of a defensible, continuously‑validated access‑control framework.
Who Is Affected – Brazilian banks and payment service providers handling cryptocurrency custody; broader financial services firms with similar high‑value asset management functions.
Recommended Actions
- Map the breach to the “manage privileged access” control objective and verify that all crypto‑custody accounts are covered by least‑privilege policies.
- Deploy continuous credential‑use monitoring and integrate logs into a central Trust Center for audit readiness.
- Conduct an immediate credential rotation for all custody‑related accounts and enforce MFA or hardware‑based authentication.
Technical Notes – The attackers leveraged stolen privileged credentials (likely obtained via phishing or insider compromise) to access internal wallet management systems. No specific CVE is cited; the vector is credential theft leading to data exfiltration of private keys. Source: The Hacker News