Slim Spider: The Brazilian Crew Quietly Robbing Banks Through Pix
A newly named criminal group is targeting Brazil's financial system with deep knowledge of instant payments and crypto custody.

Key points
- CrowdStrike named a new financially motivated group Slim Spider, tracked since at least March 2026.
- The group is based in Brazil and targets Brazilian banks and payment firms.
- Attackers show detailed knowledge of Pix, Brazil's instant payment system used by hundreds of millions of people.
- Recent activity includes stealing crypto custody secrets from a Brazilian financial institution.
- No public list of victims or dollar figures has been released yet.
A new criminal crew is quietly picking apart Brazil's banking plumbing, and the security firm CrowdStrike has finally given it a name: Slim Spider.
The group is not a nation-state spy operation. It is in this for the money. CrowdStrike says the crew has been active since at least March 2026, is based in Brazil, and knows the country's payment systems the way a locksmith knows a lock.
That matters because Brazil runs on Pix, the central bank's instant payment system that moves money between accounts in seconds, day or night. Almost every adult in the country uses it. If criminals understand how banks plug into Pix, they understand where the soft spots are.
Who is Slim Spider?
Slim Spider is a financially motivated hacking group that CrowdStrike says operates out of Brazil and hits Brazilian financial firms. In plain terms: local criminals robbing local banks, using code instead of masks.
CrowdStrike, first reported by The Hacker News, describes the crew as having "deep operational knowledge" of how Brazilian banks connect to Pix and to the broader payments network. That is not the profile of a random ransomware gang scanning the internet for open doors. It reads more like insiders, or people who used to work in the industry.
One recent intrusion involved stealing crypto custody secrets from a Brazilian financial institution. Custody secrets are the digital keys a company holds to control cryptocurrency on behalf of clients. Whoever holds those keys can, in theory, move the coins.
How are they getting in?
CrowdStrike has not published a full technical breakdown yet, so the exact break-in method is not public. What the firm has said is that the group tailors its work to Brazilian banking software and internal payment tools, rather than using generic off-the-shelf malware.
In practice, that usually means a mix of phishing emails aimed at staff, stolen employee logins, and abuse of the trusted software banks use to talk to Pix and to card networks. The failure mode here is familiar: an engineer on the payments team clicks the wrong link, and their session token becomes the attacker's session token.
One thing the post-mortem will almost certainly say is that the attackers moved through systems that were never designed to be reached from a laptop.
What it means for ordinary Brazilians
Right now, there is no public evidence that customer accounts were drained or that Pix itself is broken. The reporting points at the banks and payment firms, not at individual users.
Still, if you bank in Brazil, the sensible steps are the same ones that always help:
- Turn on every alert your bank offers for Pix transfers and card use, so a strange payment pings your phone within seconds.
- Treat any message asking you to "confirm" a Pix key, install an app, or share a code as hostile until proven otherwise.
Crypto customers of the affected institution are in a trickier spot. If custody keys were stolen, the firm holding your coins has to rotate those keys and prove the funds are still there. Ask them, in writing.
Why this story matters beyond Brazil
Slim Spider is a preview of a wider pattern. Instant payment systems are spreading fast: Pix in Brazil, UPI in India, FedNow in the United States, SEPA Instant in Europe. Each one gives criminals a new, fast rail to move stolen money before anyone notices.
The operational takeaway: if your bank plugs into an instant payment network, assume someone is already mapping how you plug in.



