Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, functioning as a comprehensive toolkit for Initial Access Brokers. Unlike standard infostealers, BraZetsu transforms compromised systems into commercial assets through deep reconnaissance capabilities targeting Iberian and Latin American corporate, financial, industrial, and law enforcement environments. The framework scans for standardized financial remittance files in Brazilian CNAB format, extracts detailed browser histories, and employs AI-enhanced data triage for target prioritization. Operating through a modular architecture with stealth techniques, BraZetsu powers the Infected Marketplace where Exilware commercializes initial access to compromised hosts. The platform allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect. Tracked since February 2026, BraZetsu demonstrates rapid technical progressi...
Indicators of Compromise
- domain: infect.online
- hash: 0e00adb0a5ca285b838af623c753b6ff
- hash: 1b6dd10ace5e6e9a5e52dbbbc5e45289
- hash: 27167134b9c5110fb4427829eff6dbad
- hash: 7a7d962cc70d1b8079fc39382ab48ae6
- hash: 7f1cba40545fa069e7f82023c82f936c
- hash: 1d83329a31c21880b9fa86644ad466dbf86021d8
- hash: 5e20d8736e86f2ebebaa5e9aa9257a2086839e47
- hash: abf6ea4a161ce9d049a6d3c3963fa73b57fba1de
- hash: f6e4fa567ac8fceb2ef79bb097e8112de1c784fb
- hash: fdaee6cb8967b547b57232c1c86e7fa61ac58a61
- hash: 0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d
- hash: 0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf
- hash: 10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c
- hash: 1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246
- hash: 30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe
- hash: 3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa
- hash: 54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700
- hash: 67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2
- hash: 91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0
- hash: 93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88
- hash: 96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042
- hash: bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8
- hash: c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138
- hash: cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78
- hash: d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99
- hash: f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17
- domain: caixaentradas1boxshop.site
- domain: caixaentradas1inboxshop.site
- domain: infectonline.store
- domain: installscenter.com
- domain: c2.installscenter.com
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem
Description
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, functioning as a comprehensive toolkit for Initial Access Brokers. Unlike standard infostealers, BraZetsu transforms compromised systems into commercial assets through deep reconnaissance capabilities targeting Iberian and Latin American corporate, financial, industrial, and law enforcement environments. The framework scans for standardized financial remittance files in Brazilian CNAB format, extracts detailed browser histories, and employs AI-enhanced data triage for target prioritization. Operating through a modular architecture with stealth techniques, BraZetsu powers the Infected Marketplace where Exilware commercializes initial access to compromised hosts. The platform allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect. Tracked since February 2026, BraZetsu demonstrates rapid technical progressi...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/"]
- Adversary
- Exilware
- Pulse Id
- 6a95a0ec07977804896dcd7a
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaininfect.online | — | |
domaincaixaentradas1boxshop.site | — | |
domaincaixaentradas1inboxshop.site | — | |
domaininfectonline.store | — | |
domaininstallscenter.com | — | |
domainc2.installscenter.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0e00adb0a5ca285b838af623c753b6ff | — | |
hash1b6dd10ace5e6e9a5e52dbbbc5e45289 | — | |
hash27167134b9c5110fb4427829eff6dbad | — | |
hash7a7d962cc70d1b8079fc39382ab48ae6 | — | |
hash7f1cba40545fa069e7f82023c82f936c | — | |
hash1d83329a31c21880b9fa86644ad466dbf86021d8 | — | |
hash5e20d8736e86f2ebebaa5e9aa9257a2086839e47 | — | |
hashabf6ea4a161ce9d049a6d3c3963fa73b57fba1de | — | |
hashf6e4fa567ac8fceb2ef79bb097e8112de1c784fb | — | |
hashfdaee6cb8967b547b57232c1c86e7fa61ac58a61 | — | |
hash0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d | — | |
hash0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf | — | |
hash10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c | — | |
hash1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 | — | |
hash30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe | — | |
hash3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa | — | |
hash54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 | — | |
hash67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2 | — | |
hash91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 | — | |
hash93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88 | — | |
hash96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 | — | |
hashbc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8 | — | |
hashc4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138 | — | |
hashcd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 | — | |
hashd881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 | — | |
hashf775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 | — |
Threat ID: 6a969252acd9273b49751a1c
Added to database: 09/01/2026, 08:52:34 UTC
Last updated: 09/01/2026, 12:37:38 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.