{"id":1476,"date":"2026-09-09T11:54:16","date_gmt":"2026-09-09T06:24:16","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1476"},"modified":"2026-09-10T14:36:42","modified_gmt":"2026-09-10T09:06:42","slug":"slim-spider-crypto-custody-cloud-devops-defense","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/","title":{"rendered":"Slim Spider Cloud Metadata Attack on Crypto Custody Secrets at a Brazilian Financial Institution"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>A compromised cloud identity can expose far more than one application or server.<\/p>\n<p>In late March 2026, Slim Spider reportedly breached a Brazilian financial institution and targeted its cryptocurrency assets and instant payment accounts. The attackers used custom scripts to obtain temporary cloud credentials, extract crypto custody secrets, and expand their access through cloud containers and Azure DevOps.<\/p>\n<p>The incident demonstrates how a cloud metadata attack can progress from stolen workload credentials to sensitive financial infrastructure. It also shows how securing endpoints, cloud identities, secret stores, and DevOps pipelines separately creates risk.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">\u2753 Who is Slim Spider?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tSlim Spider is a financially motivated cybercrime group that has targeted Brazilian financial institutions since at least March 2026. The activity cluster appears to operate from Brazil and shows detailed knowledge of the country\u2019s financial infrastructure, including Pix, digital asset platforms, and financial-sector cloud environments.<\/p>\n<p>The group\u2019s objective is financial gain. Its known tooling includes MikeDor, a custom cross-compiled backdoor written in Go that can collect information and monitor activity on compromised systems.<\/p>\n<p>Researchers have not publicly verified any aliases for Slim Spider. Although other criminal groups also target Brazilian payment systems, researchers should not link them to the same operation without evidence connecting their infrastructure or operators. <a href=\"https:\/\/www.crowdstrike.com\/en-us\/adversaries\/slim-spider\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=Slim_Spider\" target=\"_blank\" rel=\"noopener\">CrowdStrike\u2019s adversary profile<\/a> identifies Slim Spider as a distinct eCrime actor.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<p>The observed intrusion combined cloud credential theft, secret discovery, container access, and Azure DevOps pipeline abuse.<\/p>\n<table>\n<thead>\n<tr>\n<th>Attack detail<\/th>\n<th>Observed activity<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Time period<\/td>\n<td>Slim Spider has targeted Brazilian financial institutions since at least March 2026. The detailed intrusion occurred in late March 2026.<\/td>\n<\/tr>\n<tr>\n<td>Target<\/td>\n<td>A Brazilian financial institution and its cryptocurrency assets and instant payment accounts.<\/td>\n<\/tr>\n<tr>\n<td>Initial access<\/td>\n<td>The publicly available reporting does not specify how the attackers first entered the organization.<\/td>\n<\/tr>\n<tr>\n<td>Cloud metadata attack<\/td>\n<td>Custom Bash scripts queried cloud instance metadata over socket connections to obtain temporary cloud credentials.<\/td>\n<\/tr>\n<tr>\n<td>Secret discovery<\/td>\n<td>After accessing the cloud environment, the attackers enumerated secrets stored in the organization\u2019s cloud credential manager.<\/td>\n<\/tr>\n<tr>\n<td>Crypto custody impact<\/td>\n<td>The attackers exfiltrated digital asset custody secrets, including a private key. They used the <code>cast<\/code> utility from the Foundry Ethereum toolkit to derive the wallet address associated with that key.<\/td>\n<\/tr>\n<tr>\n<td>Cryptographic activity<\/td>\n<td>The malicious Bash scripts used OpenSSL to perform cryptographic signing without relying on additional third-party libraries.<\/td>\n<\/tr>\n<tr>\n<td>Container access<\/td>\n<td>Slim Spider established access to nodes in a managed cloud container cluster.<\/td>\n<\/tr>\n<tr>\n<td>Persistence and concealment<\/td>\n<td>Backdoors were deployed with names resembling legitimate infrastructure binaries. The exact persistence mechanisms were not publicly detailed.<\/td>\n<\/tr>\n<tr>\n<td>Azure DevOps abuse<\/td>\n<td>The attackers likely used compromised credentials to run malicious Azure DevOps pipelines and deploy implants across a managed Kubernetes cluster.<\/td>\n<\/tr>\n<tr>\n<td>Deception<\/td>\n<td>One implant was named <code>spi<\/code>, apparently to resemble SPI, the infrastructure supporting Brazil\u2019s Pix payment system. This was camouflage, not a confirmed false-flag operation.<\/td>\n<\/tr>\n<tr>\n<td>MFA impact<\/td>\n<td>No MFA bypass, interception, or manipulation method was disclosed.<\/td>\n<\/tr>\n<tr>\n<td>Social engineering<\/td>\n<td>No social engineering technique was identified in the reported intrusion.<\/td>\n<\/tr>\n<tr>\n<td>Ransomware or extortion<\/td>\n<td>No ransomware deployment, encryption, or extortion attempt was reported.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The case confirms that attackers exfiltrated digital asset custody material. However, public reports do not confirm whether they used the stolen private key to transfer cryptocurrency or successfully moved funds from the institution\u2019s Pix accounts.<\/p>\n<p>Separate infrastructure associated with Slim Spider included panels for scanning financial APIs, searching compromised Microsoft 365 mailboxes, and processing unauthorized Pix transfers. An exposed command-and-control panel also displayed hosts associated with multiple Brazilian banks and fintech organizations. These findings indicate broader targeting, but they do not confirm that every displayed organization suffered financial theft. The disclosed campaign details support this distinction.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/User-sentiment-Why-listening-to-employees-is-key-for-DEX.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>User sentiment: Why listening to employees is key for DEX<\/h4><p>Combine employee sentiment with telemetry to uncover hidden friction and improve digital experiences.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/employee-sentiment-analysis-dex\/\" aria-label=\"User sentiment: Why listening to employees is key for DEX\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Why this matters<\/h2>\n<p>Crypto custody security depends on more than protecting a wallet application. Private keys, signing services, deployment pipelines, workload identities, secret managers, and administrator devices can all influence who controls a transaction.<\/p>\n<p>Temporary cloud credentials also remain powerful until they expire. If a workload can request credentials from an instance metadata service, an attacker who gains execution in that workload may be able to request the same credentials. Excessive permissions can then turn a single compromised identity into access across secret stores, containers, and deployment systems.<\/p>\n<p>Traditional endpoint controls alone cannot cover this path. Financial institutions need coordinated visibility across endpoints, cloud audit logs, identity events, Kubernetes activity, and CI\/CD pipelines. They should also restrict metadata access, apply least privilege to workload identities, protect pipeline changes, and require strong approval controls for custody-related operations.<\/p>\n<h2>How Hexnode can help<\/h2>\n<h3>Hexnode UEM: Strengthen devices used for privileged access<\/h3>\n<p>Hexnode UEM can help organizations establish a consistent security baseline for managed devices used by developers, administrators, and financial operations teams.<\/p>\n<p>IT teams can enforce password and encryption policies, manage OS and application updates, distribute approved applications, and blocklist or allowlist software on supported platforms. These controls reduce the likelihood that an unmanaged application, outdated endpoint, or weak configuration becomes an entry point for cloud credential theft.<\/p>\n<p>Organizations should apply these UEM baseline checks to workstations used by engineers who configure Azure DevOps projects and CI\/CD pipelines. Hardening these privileged endpoints helps prevent attackers from harvesting Azure DevOps credentials, access tokens, and pipeline secrets at the source.<\/p>\n<p>Hexnode can also provide device compliance data to Microsoft Entra ID for Conditional Access on Android, iOS, and macOS 11 or later. Where Azure DevOps and the applicable Conditional Access policy support device-based controls, organizations can require users to access Azure DevOps resources from enrolled, compliant devices. Where the target resource and access policy support it, organizations can require an enrolled, compliant device before granting access. This capability does not currently extend Hexnode compliance reporting to Windows or Linux devices. Hexnode\u2019s Conditional Access documentation defines this platform scope.<\/p>\n<h3>Hexnode XDR: Investigate and contain endpoint activity<\/h3>\n<p>Hexnode XDR can provide security teams with visibility into threats and endpoint activity across managed Windows and macOS environments. This is relevant when attackers use an administrator or developer workstation to obtain credentials, run malicious processes, or prepare access to cloud and DevOps systems.<\/p>\n<p>Teams can use endpoint telemetry and threat-hunting queries to investigate suspicious behavior. Response actions include isolating an affected device, terminating a malicious process, quarantining a file, and running a deep scan.<\/p>\n<p>While Hexnode XDR secures Windows and macOS administrator workstations where cloud credentials or repository keys might originate, it does not extend to Linux container nodes or cloud-native runtimes. Cloud workload protection platforms (CWPPs) and cloud audit logging remain essential for container-level detection and response.<\/p>\n<p>Hexnode XDR should complement cloud-native monitoring rather than replace it. Azure DevOps audit logs, cloud identity events, secret-manager access logs, and Kubernetes telemetry remain necessary for detecting activity that occurs directly within those services.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/6-steps-To-Hexnode-Quick-Start-Guide.webp?format=webp\" class=\"resource-box__image\" alt=\"6-steps-To-Hexnode-Quick-Start-Guide\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/6-steps-To-Hexnode-Quick-Start-Guide.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/6-steps-To-Hexnode-Quick-Start-Guide-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/6-steps-To-Hexnode-Quick-Start-Guide-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/6-steps-To-Hexnode-Quick-Start-Guide-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"6-steps-To-Hexnode-Quick-Start-Guide\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Feature Resource \n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode Quick Start Guide: How to set up Hexnode for your business\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Gain valuable insights into how you can set up Hexnode UEM for your business.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/infographics\/hexnode-quick-start-guide-how-to-set-up-hexnode-for-your-business\/'>\n                            Get the Infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Closing the gaps exposed by Slim Spider<\/h2>\n<p>Slim Spider demonstrates how attackers can move through the same cloud and automation services that financial institutions use for legitimate operations. In this case, temporary cloud credentials provided access to secrets, container infrastructure, and Azure DevOps pipelines connected to high-value financial systems.<\/p>\n<p>Security teams should restrict access to instance metadata, scope workload identities to the minimum required permissions, and monitor all secret retrieval. Azure DevOps service connections and pipeline changes should require limited roles, protected branches, independent approvals, and detailed audit logging. Crypto custody operations should also separate key access, transaction creation, and transaction approval.<\/p>\n<p>Hexnode UEM can strengthen the devices used to access these environments, while Hexnode XDR can support endpoint investigation and containment on Windows and macOS. These controls must operate alongside cloud, Kubernetes, DevOps, and custody-specific security measures.<\/p>\n<p>Start by identifying every endpoint, identity, pipeline, and workload that can reach a custody secret\u2014and remove any access that is not operationally necessary.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f\u202f\u202f\u202f\u202f <\/h5><p>Sign up for Hexnode to strengthen endpoint security and reduce credential-based attack risks.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction A compromised cloud identity can expose far more than one application or server. In&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1527,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14],"class_list":["post-1476","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-supply-chain-attack","product_category-unified-endpoint-management","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Slim Spider Crypto Custody Attack Explained<\/title>\n<meta name=\"description\" content=\"Slim Spider targeted crypto custody secrets through cloud metadata and Azure DevOps. Learn how to reduce endpoint and access risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Slim Spider Crypto Custody Attack Explained\" \/>\n<meta property=\"og:description\" content=\"Slim Spider targeted crypto custody secrets through cloud metadata and Azure DevOps. Learn how to reduce endpoint and access risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-09T06:24:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-10T09:06:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Slim-Spider.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Slim Spider Cloud Metadata Attack on Crypto Custody Secrets at a Brazilian Financial Institution\",\"datePublished\":\"2026-09-09T06:24:16+00:00\",\"dateModified\":\"2026-09-10T09:06:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/\"},\"wordCount\":1286,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Slim-Spider.png?format=webp\",\"articleSection\":[\"Supply Chain Attack\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/\",\"name\":\"Slim Spider Crypto Custody Attack Explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Slim-Spider.png?format=webp\",\"datePublished\":\"2026-09-09T06:24:16+00:00\",\"dateModified\":\"2026-09-10T09:06:42+00:00\",\"description\":\"Slim Spider targeted crypto custody secrets through cloud metadata and Azure DevOps. Learn how to reduce endpoint and access risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Slim-Spider.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Slim-Spider.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Slim Spider\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/slim-spider-crypto-custody-cloud-devops-defense\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Slim Spider Cloud Metadata Attack on Crypto Custody Secrets at a Brazilian Financial Institution\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Slim Spider Crypto Custody Attack Explained","description":"Slim Spider targeted crypto custody secrets through cloud metadata and Azure DevOps. Learn how to reduce endpoint and access risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/","og_locale":"en_US","og_type":"article","og_title":"Slim Spider Crypto Custody Attack Explained","og_description":"Slim Spider targeted crypto custody secrets through cloud metadata and Azure DevOps. Learn how to reduce endpoint and access risk.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-09T06:24:16+00:00","article_modified_time":"2026-09-10T09:06:42+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Slim-Spider.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Slim Spider Cloud Metadata Attack on Crypto Custody Secrets at a Brazilian Financial Institution","datePublished":"2026-09-09T06:24:16+00:00","dateModified":"2026-09-10T09:06:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/"},"wordCount":1286,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Slim-Spider.png?format=webp","articleSection":["Supply Chain Attack"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/","url":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/","name":"Slim Spider Crypto Custody Attack Explained","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Slim-Spider.png?format=webp","datePublished":"2026-09-09T06:24:16+00:00","dateModified":"2026-09-10T09:06:42+00:00","description":"Slim Spider targeted crypto custody secrets through cloud metadata and Azure DevOps. Learn how to reduce endpoint and access risk.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Slim-Spider.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Slim-Spider.png?format=webp","width":1340,"height":700,"caption":"Slim Spider"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/slim-spider-crypto-custody-cloud-devops-defense\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Slim Spider Cloud Metadata Attack on Crypto Custody Secrets at a Brazilian Financial Institution"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1476"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1476\/revisions"}],"predecessor-version":[{"id":1526,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1476\/revisions\/1526"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1527"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}