Skip to main content

Anatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystem

0
Medium
Published: 10/02/2026 (10/02/2026, 13:14:24 UTC)
Source: AlienVault OTX General

Description

BraZetsu is a Python-based Windows malware framework used by the Brazilian threat actor Exilware. It acts as a toolkit for Initial Access Brokers, turning compromised systems into commercial assets. The malware targets corporate, financial, industrial, and law enforcement sectors in Iberia and Latin America. It harvests financial transaction files in Brazilian CNAB format, browsing histories, and digital certificates. BraZetsu supports the 'Infected Marketplace' where initial access is sold to criminal clients for further exploitation. It has evolved rapidly since early 2026, incorporating AI-enhanced reconnaissance and advanced evasion techniques.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 09:34:13 UTC

Technical Analysis

BraZetsu is a modular, Python-based malware framework attributed to the Brazilian threat actor Exilware, designed for Windows environments. Unlike typical information stealers, it functions as a comprehensive toolkit for Initial Access Brokers, enabling the commercialization of compromised systems. It targets multiple sectors including corporate, financial, industrial, and law enforcement entities primarily in Iberia and Latin America. The malware specifically collects financial transaction files formatted in the Brazilian CNAB standard, detailed browsing histories, and digital certificates. BraZetsu facilitates the 'Infected Marketplace,' a platform where initial access to infected systems is sold to criminal clients who can then deploy additional malicious payloads remotely. Since February 2026, BraZetsu has undergone rapid technical evolution, advancing from basic remote access capabilities to an AI-enhanced intelligence collection platform with sophisticated evasion techniques.

Potential Impact

BraZetsu compromises Windows systems to provide Initial Access Brokers with valuable footholds that are monetized in underground marketplaces. The malware's ability to harvest sensitive financial data, browsing histories, and digital certificates poses risks of financial fraud, espionage, and further malware deployment. Its targeting of critical sectors such as financial and law enforcement increases the potential impact on organizational security and operations. The AI-enhanced reconnaissance and modular design enable rapid adaptation and evasion, complicating detection and response efforts.

Defensive Guidance

No specific patch or remediation is indicated for BraZetsu as it is malware rather than a software vulnerability. Mitigation should focus on detection and prevention through endpoint protection, network monitoring for command and control activity (notably WebSocket C2), and restricting initial access opportunities. Organizations in affected sectors and regions should prioritize threat intelligence sharing and incident response readiness. Since this is a malware framework actively evolving, maintaining up-to-date security controls and user awareness is critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace-es/"]
Adversary
Exilware
Pulse Id
6abfae3085404615c3cf7a32

Indicators of Compromise

Domain

ValueDescriptionCopy
domaininfect.online
—
domaincaixaentradas1boxshop.site
—
domaincaixaentradas1inboxshop.site
—
domaininfectonline.store
—
domaininstallscenter.com
—
domainc2.installscenter.com
—

Hash

ValueDescriptionCopy
hash0e00adb0a5ca285b838af623c753b6ff
—
hash1b6dd10ace5e6e9a5e52dbbbc5e45289
—
hash27167134b9c5110fb4427829eff6dbad
—
hash7a7d962cc70d1b8079fc39382ab48ae6
—
hash7f1cba40545fa069e7f82023c82f936c
—
hash1d83329a31c21880b9fa86644ad466dbf86021d8
—
hash5e20d8736e86f2ebebaa5e9aa9257a2086839e47
—
hashabf6ea4a161ce9d049a6d3c3963fa73b57fba1de
—
hashf6e4fa567ac8fceb2ef79bb097e8112de1c784fb
—
hashfdaee6cb8967b547b57232c1c86e7fa61ac58a61
—
hash0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d
—
hash0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf
—
hash10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c
—
hash1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246
—
hash30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe
—
hash3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa
—
hash54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700
—
hash67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2
—
hash91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0
—
hash93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88
—
hash96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042
—
hashbc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8
—
hashc4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138
—
hashcd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78
—
hashd881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99
—
hashf775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17
—
hash6a2a339cc029b0edeaf4f0074f9c75d1
—
hash7272b34492ffd8e66c67d8144d8a00ce
—
hashbb136a3e043178421dcb2dffc0aae5e4
—
hashbd9a0e13836e45d9fd815c5d74df2bdf
—
hashd0da7e77ea47133cb5bfb39bea4daffc
—
hashd94d36888760189c49df2ef72f0768f4
—
hashdb67738197397d6e2c25e19d2a291f9d
—
hashe7e191c6ce8f91fc8a6e4d51865203c0
—
hasheadbc6522d25110c1238ead97b882304
—
hashf196eac61c5cbe47ff73ccd953c6dc68
—
hash1c46f8c6ff8dae81b0b9b6700a1f80896e532a42
—
hash20491e200ac6a524d5e33cdabc0ece1376dcde2f
—
hash212f3cdc038d100232cef73ebc26f6e903b91498
—
hash214fb9ab63fdc9ec32e52bb4e2719a4a8439904b
—
hash3926a1bb05fb7957f5082d19bb18f33d6c4b29d7
—
hashb12c22f6abb3c2257824738e08f85eeeec580252
—
hashb7cd01715aa47c2bd1078b183ca3688705446cf0
—
hashc1a3c0f167c69720c744de14ab58febc25907981
—
hashcaa54e29f2016575f0449dfa1d937fb0c73d6524
—
hashddfd868b34a388374be3f8c4e2055bb563008dcc
—
hashccb38ba4d2a574a611dafebb9bed2770
—
hash28ebfca98034e9b514656b7f3467b7c321b4c143
—

Threat ID: 6ac367e42cdf04f656e40ac6

Added to database: 10/05/2026, 09:03:32 UTC

Last enriched: 10/05/2026, 09:34:13 UTC

Last updated: 10/05/2026, 18:48:08 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses