Anatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystem
Description
BraZetsu is a Python-based Windows malware framework used by the Brazilian threat actor Exilware. It acts as a toolkit for Initial Access Brokers, turning compromised systems into commercial assets. The malware targets corporate, financial, industrial, and law enforcement sectors in Iberia and Latin America. It harvests financial transaction files in Brazilian CNAB format, browsing histories, and digital certificates. BraZetsu supports the 'Infected Marketplace' where initial access is sold to criminal clients for further exploitation. It has evolved rapidly since early 2026, incorporating AI-enhanced reconnaissance and advanced evasion techniques.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
BraZetsu is a modular, Python-based malware framework attributed to the Brazilian threat actor Exilware, designed for Windows environments. Unlike typical information stealers, it functions as a comprehensive toolkit for Initial Access Brokers, enabling the commercialization of compromised systems. It targets multiple sectors including corporate, financial, industrial, and law enforcement entities primarily in Iberia and Latin America. The malware specifically collects financial transaction files formatted in the Brazilian CNAB standard, detailed browsing histories, and digital certificates. BraZetsu facilitates the 'Infected Marketplace,' a platform where initial access to infected systems is sold to criminal clients who can then deploy additional malicious payloads remotely. Since February 2026, BraZetsu has undergone rapid technical evolution, advancing from basic remote access capabilities to an AI-enhanced intelligence collection platform with sophisticated evasion techniques.
Potential Impact
BraZetsu compromises Windows systems to provide Initial Access Brokers with valuable footholds that are monetized in underground marketplaces. The malware's ability to harvest sensitive financial data, browsing histories, and digital certificates poses risks of financial fraud, espionage, and further malware deployment. Its targeting of critical sectors such as financial and law enforcement increases the potential impact on organizational security and operations. The AI-enhanced reconnaissance and modular design enable rapid adaptation and evasion, complicating detection and response efforts.
Defensive Guidance
No specific patch or remediation is indicated for BraZetsu as it is malware rather than a software vulnerability. Mitigation should focus on detection and prevention through endpoint protection, network monitoring for command and control activity (notably WebSocket C2), and restricting initial access opportunities. Organizations in affected sectors and regions should prioritize threat intelligence sharing and incident response readiness. Since this is a malware framework actively evolving, maintaining up-to-date security controls and user awareness is critical.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace-es/"]
- Adversary
- Exilware
- Pulse Id
- 6abfae3085404615c3cf7a32
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaininfect.online | — | |
domaincaixaentradas1boxshop.site | — | |
domaincaixaentradas1inboxshop.site | — | |
domaininfectonline.store | — | |
domaininstallscenter.com | — | |
domainc2.installscenter.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0e00adb0a5ca285b838af623c753b6ff | — | |
hash1b6dd10ace5e6e9a5e52dbbbc5e45289 | — | |
hash27167134b9c5110fb4427829eff6dbad | — | |
hash7a7d962cc70d1b8079fc39382ab48ae6 | — | |
hash7f1cba40545fa069e7f82023c82f936c | — | |
hash1d83329a31c21880b9fa86644ad466dbf86021d8 | — | |
hash5e20d8736e86f2ebebaa5e9aa9257a2086839e47 | — | |
hashabf6ea4a161ce9d049a6d3c3963fa73b57fba1de | — | |
hashf6e4fa567ac8fceb2ef79bb097e8112de1c784fb | — | |
hashfdaee6cb8967b547b57232c1c86e7fa61ac58a61 | — | |
hash0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d | — | |
hash0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf | — | |
hash10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c | — | |
hash1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 | — | |
hash30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe | — | |
hash3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa | — | |
hash54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 | — | |
hash67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2 | — | |
hash91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 | — | |
hash93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88 | — | |
hash96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 | — | |
hashbc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8 | — | |
hashc4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138 | — | |
hashcd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 | — | |
hashd881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 | — | |
hashf775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 | — | |
hash6a2a339cc029b0edeaf4f0074f9c75d1 | — | |
hash7272b34492ffd8e66c67d8144d8a00ce | — | |
hashbb136a3e043178421dcb2dffc0aae5e4 | — | |
hashbd9a0e13836e45d9fd815c5d74df2bdf | — | |
hashd0da7e77ea47133cb5bfb39bea4daffc | — | |
hashd94d36888760189c49df2ef72f0768f4 | — | |
hashdb67738197397d6e2c25e19d2a291f9d | — | |
hashe7e191c6ce8f91fc8a6e4d51865203c0 | — | |
hasheadbc6522d25110c1238ead97b882304 | — | |
hashf196eac61c5cbe47ff73ccd953c6dc68 | — | |
hash1c46f8c6ff8dae81b0b9b6700a1f80896e532a42 | — | |
hash20491e200ac6a524d5e33cdabc0ece1376dcde2f | — | |
hash212f3cdc038d100232cef73ebc26f6e903b91498 | — | |
hash214fb9ab63fdc9ec32e52bb4e2719a4a8439904b | — | |
hash3926a1bb05fb7957f5082d19bb18f33d6c4b29d7 | — | |
hashb12c22f6abb3c2257824738e08f85eeeec580252 | — | |
hashb7cd01715aa47c2bd1078b183ca3688705446cf0 | — | |
hashc1a3c0f167c69720c744de14ab58febc25907981 | — | |
hashcaa54e29f2016575f0449dfa1d937fb0c73d6524 | — | |
hashddfd868b34a388374be3f8c4e2055bb563008dcc | — | |
hashccb38ba4d2a574a611dafebb9bed2770 | — | |
hash28ebfca98034e9b514656b7f3467b7c321b4c143 | — |
Threat ID: 6ac367e42cdf04f656e40ac6
Added to database: 10/05/2026, 09:03:32 UTC
Last enriched: 10/05/2026, 09:34:13 UTC
Last updated: 10/05/2026, 18:48:08 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.