BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
BraZetsu malware turns Windows hosts into commercial assets for an underground marketplace.
Summary
BraZetsu is a sophisticated Python-based Windows malware framework that functions as a master toolkit for Initial Access Brokers (IABs), transforming compromised systems into valuable commercial assets. The malware, developed by threat actors tracked as Exilware, utilizes AI for data triage and target prioritization, and fuels the Infected Marketplace where access to compromised hosts is sold as a service.
Full text
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory Swati KhandelwalSep 03, 2026Cybercrime / Artificial Intelligence Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets," Group-IB malware analysts Julio Guapo Menezes and Miguel Salazar said in a technical report. "The framework exhibits high operational maturity, utilizing a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis." BraZetsu is a portmanteau of "Brazil" and "Zetsu," a fictional character from the Japanese Manga series Naruto who is known to operate as a threat from the shadows. The naming is inspired by the fact that the initial access tool stealthily infiltrates target networks to conduct highly destructive follow-on attacks. The threat actors, tracked as Exilware, are believed to be native Portuguese speakers. The Singapore-headquartered company said BraZetsu is primarily scoped to target Iberian and Latin American targets in e-commerce, corporate, financial, industrial, law enforcement, and other environments. Evidence points to heavy use of generative artificial intelligence (AI) for not just malware development, but also backend data triage and target prioritization. The malware harbors capabilities to conduct deep reconnaissance and scan victim networks. For financial remittance files, such as those in the Brazilian CNAB format, a fixed-width text file standard used for electronic data interchange (EDI) of financial transactions between companies and banks in Brazil. It's also equipped to extract detailed browser histories to get an understanding of victim activity. BraZetsu forms the foundation for the Infected Marketplace (aka "Banco de Infects", "infect[.]online"), a platform where the threat actor monetizes initial access to compromised hosts for an initial deposit of roughly $5.80. The threat actor was first discovered on February 2, 2026, rapidly evolving its toolset from a basic remote access trojan to the AI-enhanced intelligence-gathering framework it is today. "By functioning as a service-enabled platform, the marketplace allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect across the regional ecosystem," the researchers said. "The marketplace functions as an access-as-a-service operation, in which other criminals can purchase entry points into victims' systems. Once a criminal purchases access through the marketplace, they can deploy malicious payloads via a specialized platform feature. This allows buyers to remotely execute their own malware or tools on the compromised systems without needing to establish the initial foothold themselves." The modular Python framework, per Group-IB, was first seen in early May 2026, and offers a way for the operators to catalog compromised systems as "tradable assets" for secondary threat actors on the marketplace. It supports the following functions - Scans infected hosts and uses generative AI to triage data and prioritize high-value targets for IABs Collects digital certificates, browser histories from Google Chrome, Microsoft Edge, Brave, Vivaldi, and Opera, and financial files while tracking user behavior through screen captures Attempts to locate corporate financial remittance files in the Brazilian Federation of Banks' CNAB format Relies on the WebSocket protocol to maintain persistent communication with the Infected Marketplace BraZetsu also shares some level of overlap with CNABHunter, a custom Python tool that systemically scans local and network directories for CNAB files, parses financial transaction records, and exfiltrates payment metadata to a dedicated HTTP-based infrastructure. Furthermore, CNABHunter polls a remote server for operator-issued orders. "When instructed, it automatically rewrites the original CNAB files by replacing legitimate payment information with attacker-controlled banking details, PIX keys, or barcodes," Group-IB said. "This workflow is specifically designed to facilitate financial fraud against corporate payment processes." On the other hand, BraZetsu is more geared towards initial access rather than an implement for financial fraud. Besides performing broad host reconnaissance and gathering CNAB-related files, it facilitates autonomous data collection, interactive, hands-on operations through remote shell command execution, and the deployment of additional worker modules. The core aspect that ties them together is the directory list used to locate CNAB-related files. It's suspected that the developers associated with BraZetsu incorporated the same functionality after seeing a "profitable opportunity." This assessment is based on the fact that BraZetsu was discovered in the wild a day after CNABHunter was publicly disclosed by a researcher named @johnk3r on X. Exactly how this malware is delivered to victims remains unclear at this stage. However, social engineering is the most likely culprit. The starting point is a loader that masquerades as Microsoft Edge and is downloaded from a distribution domain named "caixaentradas1inboxshop[.]site." An analysis of the files associated with the domain has uncovered Visual Basic Script (VBS) files responsible for downloading the next stage of the attack. Interestingly, the same domain has been used to deliver the Ousaban banking trojan. In May 2026, Fortinet FortiGuard Labs said it identified an email phishing attack targeting users in the Iberian Peninsula with an MSI downloader that deploys Ousaban. "The phishing PDF tricks victims into visiting a malicious webpage that scans the user's environment," Fortinet said in a report published in July. "If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack. The final payload is an EXE file that is dropped onto the victim’s computer and executed by the VBS script." The VBS file is designed to retrieve a steganographic PNG image that mimics a PDF document, which then extracts a ZIP file from the image and extracts from it the Ousaban DLL. The final payload is then run via DLL sideloading or process injection. Like in the case of Ousaban, BraZetsu uses a Pastebin URL to extract the C2 information. It also incorporates dedicated functions to obtain the user's active application window title and, if it contains common banking keywords; enumerate environment variables, network ports, and running processes; run shell commands; capture screenshots; fetch recently opened files; and locate common Enterprise Resource Planning (ERP) installation directories. In all, five distinct versions of the malware have been detected in the wild to date, with the earliest iteration dating back to February 9, 2026. The third generation is notable for narrowing its operational focus to corporate targets in Brazil. That said, the threat actor has been observed advertising access to two compromised hosts located in the U.S. around the same time. "BraZetsu functions as the primary malware framework supporting Exilware's Initial Access Broker (IAB) operation by establishing initial footholds and continuously replenishing the Infect Marketplace inventory," Group-IB said. A deeper hunt for artifacts matching the naming convention used by Exilware has also identified an IP address ("38.242.246[.]176") that has been previously tied to AgenteV2, a Python-based backdoor that has targeted Brazilian users via phishing lures impersonating judicial summons. The malware is engineered to stream a victim's screen to the attacker in real-time to facilit
Indicators of Compromise
- domain — infect[.]online