VMTech
Discuss a project

BraZetsu fuels a marketplace for access to compromised Windows hosts

BraZetsu fuels a marketplace for access to compromised Windows hosts

Group-IB has disclosed BraZetsu, a modular Python-based Windows malware framework used by the threat actor it tracks as Exilware to supply an underground access marketplace. The platform, called Infected Marketplace, or “Banco de Infects,” offers entry to compromised hosts for an initial deposit of roughly $5.80.

Researchers identified five versions in the wild, with the earliest iteration dating to February 9, 2026. BraZetsu was first seen as a modular framework in early May and evolved from a basic remote-access trojan into a reconnaissance and intelligence-gathering tool that classifies compromised systems as tradable assets.

Reconnaissance designed for resale

BraZetsu scans infected hosts and victim networks, collects digital certificates, browser histories and financial files, and captures screenshots. It can retrieve recently opened files, enumerate environment variables, network ports and running processes, identify active application-window titles, execute shell commands and search common Enterprise Resource Planning installation directories.

The malware targets browser data from Google Chrome, Microsoft Edge, Brave, Vivaldi and Opera. It also seeks files in the Brazilian CNAB format, a fixed-width standard used for electronic data interchange of financial transactions between businesses and banks in Brazil.

Group-IB said Exilware uses generative AI for malware development as well as backend data triage and target prioritisation. The framework evaluates a machine through hardware profiling, software-environment analysis and network-infrastructure mapping, allowing the operator to categorise and price access based on the victim’s perceived value.

Marketplace model expands the risk

BraZetsu maintains persistent communication with Infected Marketplace through WebSocket. Once another criminal buys access, a specialised platform feature lets that buyer remotely execute secondary malware or tools on the already compromised machine, without establishing the initial foothold.

That model separates the initial compromise from later malicious activity. Group-IB described BraZetsu as the primary framework supporting Exilware’s Initial Access Broker operation and continuously replenishing marketplace inventory. The group is believed to consist of native Portuguese speakers, and the malware has primarily targeted Iberian and Latin American organisations in e-commerce, corporate, financial, industrial and law-enforcement environments.

Links to CNAB-focused tooling and phishing delivery

BraZetsu shares overlap with CNABHunter, another custom Python tool that scans local and network directories for CNAB files, parses transaction records and sends payment metadata to dedicated HTTP infrastructure. CNABHunter can also rewrite payment details, PIX keys or barcodes when instructed, whereas BraZetsu is oriented chiefly towards initial access and broader host intelligence.

Researchers noted that both tools use the same directory list to locate CNAB-related files. BraZetsu appeared in the wild one day after CNABHunter was publicly disclosed, leading Group-IB to suspect that its developers incorporated the functionality after identifying a profitable opportunity.

The exact delivery method for BraZetsu is not yet known, although Group-IB considers social engineering the most likely route. A loader masquerading as Microsoft Edge was downloaded from a domain that also delivered the Ousaban banking trojan. Associated Visual Basic Script files download later stages, while BraZetsu uses a Pastebin URL to obtain command-and-control information.

For businesses, the practical implication is to investigate phishing-driven script execution, counterfeit browser installers and unexpected host reconnaissance as potential initial-access activity, particularly on endpoints with browser data, ERP deployments or CNAB payment workflows.

#cybersecurity#malware#windowssecurity#threatintelligence
Open analytics
On the site 0 views
min read 4 03.09.2026
Instagram

BraZetsu fuels a marketplace for access to compromised Windows hosts

Open the post on Instagram ↗