Slim Spider Targets Brazilian Financial Institution in Crypto Custody Data Theft Campaign
Cybercriminal group Slim Spider has targeted a Brazilian financial institution in an operation focused on stealing sensitive information associated with cryptocurrency custody operations.

The attack highlights the increasing interest of threat actors in financial institutions managing digital assets, where access to credentials, cryptographic material, and custody infrastructure can provide significant financial value.
Key Takeaways
- Slim Spider targeted a Brazilian financial institution involved in cryptocurrency-related operations.
- The attackers focused on obtaining sensitive crypto custody information and secrets.
- Cryptocurrency custody infrastructure remains an attractive target because compromised credentials or cryptographic secrets can potentially enable unauthorized access to digital assets.
- The campaign demonstrates the need for stronger controls around privileged accounts, credentials, cryptographic keys, and digital-asset infrastructure.
- Financial organizations should maintain continuous monitoring for suspicious access and anomalous activity involving systems that handle cryptocurrency assets.
Affected Assets
| Asset / System | Risk |
|---|---|
| π Crypto Custody Systems | Unauthorized access to digital-asset management infrastructure |
| π Cryptographic Keys & Secrets | Potential compromise of sensitive signing or authentication material |
| π€ Privileged Accounts | Account takeover and unauthorized administrative access |
| π» Endpoints & Servers | Potential entry points for credential and data theft |
| π° Digital-Asset Platforms | Potential manipulation or unauthorized access to cryptocurrency operations |
| π Third-Party Integrations | Possible abuse of connected services and credentials |
Affected Organization: Brazilian financial institution
Sector: Financial Services / Cryptocurrency
Potentially Targeted Assets:
- Cryptocurrency custody infrastructure
- Privileged accounts and credentials
- Cryptographic keys and secrets
- Digital-asset management systems
- Systems supporting cryptocurrency transactions and custody operations
Threat Actor
Threat Group: Slim Spider
Primary Objective: Theft of sensitive cryptocurrency custody information and secrets.
The targeting reflects a broader trend in which financially motivated threat actors are increasingly focusing on organizations responsible for managing or safeguarding digital assets.
Why This Matters
Compromise of cryptocurrency custody environments can have consequences beyond conventional data theft. Attackers gaining access to privileged credentials, cryptographic secrets, or custody systems could potentially use that access to facilitate unauthorized transactions or additional attacks.
For financial institutions, protecting digital-asset infrastructure therefore requires controls that go beyond traditional endpoint and network security.
Mitigation & Security Recommendations
Organizations operating cryptocurrency custody or digital-asset infrastructure should:
Implement strong privileged access controls
- Apply least-privilege principles.
- Use privileged access management (PAM) for administrative accounts.
- Regularly review and remove unnecessary privileges.
Protect cryptographic keys and secrets
- Store sensitive keys in appropriately secured hardware or dedicated key-management systems.
- Avoid storing secrets in plaintext or insecure configuration files.
- Rotate credentials and secrets following suspected compromise.
Strengthen authentication
- Enforce phishing-resistant MFA for privileged and sensitive accounts.
- Disable legacy authentication mechanisms where possible.
Monitor custody infrastructure
- Establish centralized logging and continuous monitoring.
- Detect unusual authentication, privilege escalation, key-access, and transaction activity.
- Create specific detections for access to cryptocurrency custody systems.
Segment critical systems
- Isolate cryptocurrency custody infrastructure from general corporate networks.
- Restrict administrative access to approved systems and trusted network segments.
Enhance incident-response readiness
- Maintain an incident-response playbook specifically covering digital-asset infrastructure.
- Establish procedures for immediately disabling compromised credentials and isolating affected systems.
- Regularly test incident-response and recovery procedures.
Conduct regular security assessments
- Perform penetration testing and security assessments of custody platforms and supporting infrastructure.
- Continuously assess exposed services, privileged accounts, and third-party integrations.
Risk Rating
Threat Severity: High
Primary Risk: Unauthorized access to cryptocurrency custody infrastructure, credentials, and cryptographic secrets.
Bottom Line
The Slim Spider campaign demonstrates why cryptocurrency custody environments are becoming increasingly attractive to cybercriminals. Financial institutions managing digital assets should treat custody systems and cryptographic secrets as high-value assets, combining strong access controls, network segmentation, continuous monitoring, and tested incident-response procedures to reduce the risk of compromise.
Related reporting
Attackers Use Passkey-Themed Phishing to Hijack Microsoft Cloud Accounts and Steal Data
Threat actors are using passkey-themed social engineering to compromise Microsoft 365 accounts and gain access to sensitive cloud data, according to Microsoft Threat Intelligence.
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic says it identified and disrupted seven industrial-scale attempts to extract capabilities from its Claude AI models, attributing the activity to China-based AI laboratories.
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Cybercriminals and state-sponsored threat actors are increasingly using artificial intelligence to automate portions of real-world cyberattacks, with Anthropic revealing that its Claude models were incorporated into multi-stage operations involving reconnaissance, exploitation, credential theft and data exfiltration.


