BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have uncovered BraZetsu, a sophisticated Python-based Windows malware framework used by the threat actor Exilware to turn compromised systems into tradable assets for an underground initial-access marketplace. The malware performs deep reconnaissance, collects browser histories, digital certificates, financial files, screenshots, and network information, while using AI-assisted triage to identify high-value victims across Latin America and the Iberian Peninsula.
Cybersecurity researchers at Group-IB have disclosed a sophisticated malware framework called BraZetsu that is designed to commercialise access to compromised Windows systems.
Unlike traditional information stealers that primarily collect credentials and immediately exfiltrate data, BraZetsu operates as a broader Initial Access Broker toolkit.
Its purpose is to profile infected machines, determine their commercial value, and list them as access opportunities in a criminal marketplace known as the Infected Marketplace, also referred to as Banco de Infects.
BraZetsu Linked to Exilware
Group-IB attributes the malware with high confidence to a Brazilian threat actor tracked as Exilware.
Researchers believe the operators are native Portuguese speakers and say the malware primarily targets organisations across:
- Brazil
- Latin America
- Spain
- Portugal
Industries of interest include:
- Financial services
- E-commerce
- Corporate environments
- Industrial organizations
- Law enforcement
- ERP environments
- Other high-value commercial networks
The framework's focus suggests the operators are particularly interested in systems that can be monetised through financial fraud or resold as enterprise access.
Compromised Systems Become Marketplace Inventory
One of BraZetsu's most distinctive features is its role in the Infected Marketplace.
The marketplace operates under an access-as-a-service model.
Criminal customers can purchase access to already compromised systems without needing to perform the initial intrusion themselves.
After buying access, attackers can remotely deploy additional malware or tools onto the victim machine.
This effectively separates the attack lifecycle into two businesses:
Initial compromise and reconnaissance
→ performed by Exilware
Post-exploitation and monetisation
→ performed by marketplace customers
This model significantly lowers the barrier for secondary attackers because they can purchase a ready-made foothold instead of performing phishing or exploitation independently.
Access Costs Only a Few Dollars
Researchers found that access to the marketplace could begin with an initial deposit of approximately $5.80.
That low price demonstrates how commoditised compromised infrastructure has become.
An infected corporate endpoint may therefore be sold cheaply even though it could ultimately provide access to:
- Financial systems
- Corporate credentials
- ERP software
- Internal networks
- Payment workflows
- Sensitive customer data
The true value of the access depends on what BraZetsu discovers during reconnaissance.
AI Helps Prioritise High-Value Victims
One of the most notable findings is BraZetsu's apparent use of generative AI.
Group-IB says the framework's codebase and operational logs show strong indications that AI was used during development and may also assist with backend data analysis.
AI-assisted functions may include:
- Victim profiling
- Data triage
- Identifying high-value systems
- Prioritising marketplace listings
- Interpreting hardware and software environments
- Network infrastructure mapping
Researchers believe the system can automatically evaluate the commercial potential of compromised machines.
This creates a more scalable model for criminal operations because attackers do not need to manually review every infected endpoint.
Deep Reconnaissance of Windows Systems
BraZetsu collects far more information than a typical credential stealer.
Its capabilities include:
- Enumerating environment variables
- Identifying open network ports
- Listing running processes
- Capturing screenshots
- Tracking active application windows
- Searching recently opened files
- Locating ERP installation directories
- Collecting digital certificates
- Extracting browser histories
- Performing network reconnaissance
- Executing shell commands
The malware monitors user activity and attempts to understand what type of system it has compromised.
This data helps operators classify the victim before listing access for sale.
Browser History Used to Understand Victims
BraZetsu can extract browsing histories from several popular browsers, including:
- Google Chrome
- Microsoft Edge
- Brave
- Vivaldi
- Opera
Browser history provides attackers with useful context.
For example, it may reveal whether a victim regularly accesses:
- Banking portals
- Internal dashboards
- Corporate applications
- E-commerce platforms
- Payment providers
- Administrative systems
This contextual intelligence can increase the marketplace value of a compromised host.
BraZetsu Searches for Brazilian CNAB Files
The malware specifically searches for CNAB financial remittance files.
CNAB is a fixed-width banking file format widely used in Brazil to exchange financial transaction information between companies and banks.
Organisations may use these files for:
- Payroll
- Bulk payments
- Supplier payments
- Account reconciliation
- Banking instructions
BraZetsu searches local and network directories for these files and collects information about their presence.
This focus reflects the malware's strong alignment with Brazilian financial environments.
Connection to CNABHunter
Researchers identified functional overlap between BraZetsu and another Python tool called CNABHunter.
CNABHunter is designed specifically to locate CNAB files and can modify payment information inside them.
According to Group-IB, CNABHunter can replace legitimate payment data with:
- Attacker-controlled banking information
- PIX keys
- Fraudulent barcodes
This enables direct manipulation of corporate payment workflows.
BraZetsu itself appears to focus more on initial access and reconnaissance, but both tools search many of the same directory paths associated with financial remittance files.
WebSocket Connection Keeps Access Persistent
BraZetsu communicates with the Infected Marketplace using the WebSocket protocol.
This provides persistent bidirectional communication between the victim machine and attacker infrastructure.
Through this connection, operators can:
- Receive reconnaissance results
- Issue commands
- Execute shell instructions
- Deploy additional modules
- Maintain remote access
Persistent WebSocket traffic can also blend into legitimate web application traffic, making it useful for long-lived command-and-control channels.
Delivery Method Still Unclear
Researchers have not confirmed exactly how all BraZetsu infections begin.
However, evidence suggests that social engineering and phishing are likely involved.
One observed loader masqueraded as Microsoft Edge and was downloaded from the domain:
caixaentradas1inboxshop[.]site
Related infrastructure has also been associated with Visual Basic Script files used to download additional malicious payloads.
Infrastructure Overlap With Ousaban
The same distribution domain has previously been linked to the Ousaban banking Trojan.
Earlier campaigns targeting users in Spain and Portugal used phishing PDFs that redirected victims to malicious websites.
Those sites could determine whether users were located in Spain or Portugal and then deliver a VBS downloader.
The attack chain used:
- Phishing PDFs
- VBS scripts
- Steganographic PNG files
- ZIP extraction
- DLL sideloading or process injection
BraZetsu shares several operational characteristics with this broader malware ecosystem.
Pastebin Used for Command-and-Control Configuration
BraZetsu also uses Pastebin to retrieve command-and-control information.
This is a common technique because public paste services can act as dead-drop resolvers.
Instead of hardcoding a single C2 domain in every sample, attackers can retrieve updated infrastructure dynamically.
This makes it easier to change backend servers without rebuilding malware.
Five Versions Detected
Researchers have identified at least five distinct BraZetsu versions in the wild.
The earliest version dates back to February 2026.
Later versions became increasingly sophisticated and eventually shifted toward a stronger focus on Brazilian corporate environments.
Researchers also observed Exilware advertising access to compromised systems in the United States, demonstrating that the framework is technically capable of operating beyond its primary regional focus.
BraZetsu May Be Related to AgenteV2
Group-IB also identified infrastructure and code overlap with another Python-based malware family called AgenteV2.
AgenteV2 has targeted Brazilian users through phishing lures impersonating judicial summons.
The malware can stream the victim's screen in real time, particularly when banking portals are opened.
Based on shared:
- Code
- Infrastructure
- Tradecraft
- Functional capabilities
Group-IB assesses with high confidence that AgenteV2 and BraZetsu represent the same underlying initial-access malware framework.
Analysis and context
BraZetsu demonstrates an important shift in cybercrime:
Malware is increasingly being used to manufacture inventory for criminal marketplaces.
The infected endpoint is no longer merely a victim.
It becomes a product.
Initial Access Has Become a Commercial Commodity
The Initial Access Broker ecosystem has existed for years.
Traditionally, brokers compromise organisations and sell access through:
- VPN accounts
- RDP credentials
- Web shells
- Corporate credentials
BraZetsu industrialises that model.
Instead of manually evaluating each victim, the malware performs reconnaissance and collects enough information to determine whether the host is commercially valuable.
This makes access brokerage more scalable.
AI Makes Criminal Prioritisation More Efficient
AI's role is particularly concerning because the biggest bottleneck in large malware campaigns is often not infection.
It is analysis.
An attacker may compromise thousands of endpoints, but manually deciding which ones are worth further attention takes time.
AI-assisted triage can potentially automate questions such as:
- Is this a corporate machine?
- Does it contain banking data?
- Is ERP software installed?
- Are valuable certificates present?
- What internal network can it reach?
- Is this victim worth selling?
This turns generative AI into an operational force multiplier.
The Victim Is Evaluated Like an Asset
BraZetsu's model resembles legitimate business asset valuation.
A compromised machine can be priced based on characteristics such as:
- Organization type
- Country
- Hardware profile
- Installed software
- Financial activity
- Internal connectivity
- Available credentials
This represents a mature criminal business model.
The malware is not simply stealing data.
It is gathering market intelligence about the victim itself.
Financial Files Create Direct Fraud Opportunities
The focus on CNAB files is especially important.
Corporate financial remittance systems process high-value payment instructions.
Even if BraZetsu itself mainly performs reconnaissance, identifying where those files are stored can make the compromised machine significantly more attractive to fraud-oriented buyers.
Combined with tools such as CNABHunter, attackers could potentially move from:
network access
→ financial file discovery
→ payment manipulation
This bridges cyber intrusion and direct financial fraud.
Marketplace Access Multiplies Threat Actors
The Infected Marketplace also creates a threat-multiplier effect.
The organisation may initially be compromised by Exilware.
But once the access is sold, a completely different attacker may take control.
That second attacker could deploy:
- Ransomware
- Credential stealers
- Remote access Trojans
- Data exfiltration tools
- Banking malware
- Cryptominers
This makes attribution and incident response more difficult because the original access broker and the final attacker may be unrelated.
Browser History Is High-Value Intelligence
The use of browser history deserves special attention.
Security discussions often focus on stored passwords and cookies.
But browsing history itself is valuable intelligence.
It can reveal:
- Which bank the organisation uses
- Which internal services employees access
- Which cloud applications are important
- Which business systems are regularly used
- Which payment platforms are active
This information can help attackers design more precise follow-on attacks.
Defenders Need to Detect Reconnaissance, Not Just Data Theft
BraZetsu demonstrates why organisations should monitor post-compromise reconnaissance behaviour.
Suspicious activity may include:
- Mass directory enumeration
- Browser-history access
- ERP directory discovery
- Network scanning
- Financial-file searches
- Screenshot capture
- Certificate enumeration
- Unusual WebSocket connections
Detecting these behaviours early may allow defenders to remove the attacker before the compromised endpoint is sold to another criminal.
The Broader Security Lesson
BraZetsu shows that malware ecosystems are becoming increasingly service-oriented and data-driven.
The attacker's objective may not be to complete the final intrusion themselves.
Instead, they can specialise in:
Compromise
→ profile
→ classify
→ price
→ sell
Generative AI makes this model more scalable because it can reduce the human effort required to evaluate compromised assets.
For organisations, the defensive implication is clear:
A compromised endpoint should be treated as the beginning of a potentially larger criminal supply chain, not as an isolated malware infection.
Source: Group-IB Threat Intelligence research and additional reporting by The Hacker News, September 2026.