Skip to main content
Emerging ThreatsMalware & Ransomware

BraZetsu Malware Fuels Underground Marketplace for Compromised Hosts

Shadowy figure inspects computer device in dimly lit underground market stall.

"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets," Group-IB malware analysts Julio Guapo Menezes and Miguel Salazar said in a technical report.

What BraZetsu is and who is behind it

BraZetsu is a Python-based Windows malware framework that Group-IB says functions as an initial access toolkit for an actor tracked as Exilware. The framework is described as modular, stealthy enough that some samples were undetected on VirusTotal at the time of analysis, and rapidly evolved from a basic remote-access trojan to an AI-enhanced intelligence-gathering platform after its discovery on February 2, 2026. Group-IB reports that Exilware appears to be native Portuguese speakers and that the malware is primarily scoped against targets in the Iberian Peninsula and Latin America across e-commerce, corporate, financial, industrial, and law-enforcement environments.

Technical capabilities: reconnaissance, data triage, and CNAB targeting

According to Group-IB, BraZetsu combines broad host reconnaissance with generative AI-driven triage to identify high-value systems. The framework:

  • scans infected hosts and uses generative AI to prioritize targets;
  • collects digital certificates, browser histories from Google Chrome, Microsoft Edge, Brave, Vivaldi, and Opera, and captures screenshots and active window titles to track user behavior;
  • attempts to locate corporate financial remittance files in Brazil's CNAB fixed-width format and fetches recently opened files and ERP installation directories;
  • maintains persistent communication via the WebSocket protocol and supports remote shell execution and deployment of worker modules.

Group-IB also links BraZetsu to a broader workflow that treats compromised systems as commercial assets: the malware profiles hardware and software environments and assigns a marketplace price based on assessed commercial potential.

Connection to CNABHunter, AgenteV2, and monetization infrastructure

Group-IB documents overlap between BraZetsu and CNABHunter, a custom Python tool that scans for CNAB files, parses payment metadata, and can rewrite remittance files to substitute attacker-controlled banking details, PIX keys, or barcodes. CNABHunter polls a remote server for operator-issued orders, and Group-IB notes that BraZetsu was discovered one day after CNABHunter was publicly disclosed by researcher @johnk3r on X—leading analysts to conclude the CNAB-oriented capability was likely incorporated after seeing a profitable opportunity.

Separately, Group-IB ties an IP address, 38.242.246[.]176, to AgenteV2—a Python backdoor that streams victims’ screens for financial fraud—and assesses with high confidence that AgenteV2 and BraZetsu share a single initial-access framework based on shared codebase, tradecraft, infrastructure, and capabilities.

Delivery, reuse of infrastructure, and links to other campaigns

Exactly how BraZetsu is delivered remains unclear, but Group-IB and other vendors point to social-engineering lures. Analyses show a loader posing as Microsoft Edge downloaded from a distribution domain named caixaentradas1inboxshop[.]site. Files tied to that domain include Visual Basic Script (VBS) downloaders; the same domain has been used to deliver the Ousaban banking trojan. Fortinet FortiGuard Labs reported a related campaign in May 2026 that used an MSI downloader and a phishing PDF which, if the victim was in Spain or Portugal, would fetch a VBS that drops an EXE via a steganographic PNG and DLL sideloading or process injection.

Like Ousaban, BraZetsu uses Pastebin URLs to extract C2 information and includes functions to enumerate environment variables, network ports, running processes, and to capture screenshots—behaviours suited to both reconnaissance and immediate fraud when banking applications are detected.

Infected Marketplace (Banco de Infects) and the economics of access

Group-IB links BraZetsu to the Infected Marketplace—also called "Banco de Infects" or infect[.]online—where initial access is commercialized. The marketplace lists access for an initial deposit of roughly $5.80 and allows criminal customers to remotely execute secondary payloads on purchased systems. That access-as-a-service model creates a persistent multiplier effect: Exilware supplies catalogued, triaged hosts and buyers deploy follow-on malware without needing the original foothold.

Group-IB has detected five distinct BraZetsu versions in the wild, with the earliest iteration from February 9, 2026. The third generation narrowed focus to corporate targets in Brazil, though vendors observed advertisements for two compromised hosts in the U.S. during the same period.

What this means for Brazilian financial institutions, enterprise defenders, and initial-access buyers

Brazilian financial institutions: The explicit targeting of CNAB-format remittance files and the documented capability to rewrite payment details make corporate payments processes a clear risk. The Brazilian Federation of Banks’ file format is named directly in Group-IB’s analysis.

Enterprise defenders and security teams in Iberia and Latin America: BraZetsu’s AI-driven triage and persistent WebSocket communications raise the bar for detection and incident prioritization—teams should watch for anomalous WebSocket traffic, Pastebin-based C2 indicators, and artifacts tied to the caixaentradas1inboxshop[.]site domain and VBS downloaders.

Initial-access buyers and secondary operators: The marketplace model documented by Group-IB demonstrates how low-cost access, once catalogued and priced by AI assessment, can rapidly be weaponized by other actors—expanding the reach of a single IAB operation across sectors and geographies.

BraZetsu's combination of generative AI, targeted financial-file discovery, and an explicit marketplace for tradeable access reframes initial access as inventory—priced, catalogued, and trafficked. The record supplied by Group-IB ties that capability to existing commodity tradecraft and reuse of infrastructure, but leaves the exact initial delivery chain and actor motivations open for further forensic work.

Source: The Hacker News — BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory