BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation — Threadlinqs Intelligence
As of 2026-08-31, BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation is a high-severity malware threat attributed to Exilware, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-2250 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Exilware · FINANCIAL
Group-IB identified BraZetsu, a Nuitka-compiled Python Windows malware framework operated by Brazilian actor Exilware, that turns compromised systems into commercialized assets sold via the "Infected
BraZetsu is a Python-based Windows malware framework, compiled to native executables with Nuitka, that Group-IB attributes with high confidence to the Brazilian threat actor Exilware. Rather than a conventional banking trojan, BraZetsu functions as an initial-access-broker (IAB) toolkit: it performs deep host reconnaissance (system, process, registry, and network enumeration across roughly 27 discovery functions), harvests Chromium-family browser history and profile data via direct SQLite queries, scans for Brazilian CNAB240/CNAB400 remittance files and ERP software (SAP, TOTVS, Senior, Sankhya, Alterdata, Nasajon), extracts PFX/P12 digital certificates, and pulls CPF/CNPJ personal identifiers via regex. Captured intelligence is automatically tagged across 20+ categories (e-commerce platforms, EDR products, law-enforcement hostname prefixes, SCADA/ICS software, healthcare ERPs, cryptocurrency wallets, and banking-security agents) to price and market each infected host.
Operators reach infected hosts through a WebSocket-over-TLS channel on port 8443, supporting interactive remote-shell execution and SD/HD screenshot capture. Configuration is delivered via a Pastebin dead-drop resolver, XOR-encrypted with the key "p4st3_s3cr3t_k3y" and Base64-encoded, letting operators rotate C2 infrastructure without recompiling the implant. The latest (v5) build adds an AI-assisted layer: internal log strings reference collecting "hardware and machine port metadata for server AI" and flagging files as "priority target[s] for AI," indicating a backend model triages and prioritizes stolen data before it is listed for sale.
Access to compromised hosts is monetized through the "Infected Marketplace" (Portuguese: "Banco de Infects"), reachable at infect[.]online and infectonline[.]store and hosted on a Contabo GmbH VPS at 38.242.246.176. Buyers fund accounts with a minimum ~BRL 30 (~$5.80 USD) deposit via the NowPayments cryptocurrency processor and must settle within 24-49 hours depending on infection volume; Exilware operates the marketplace with a secondary vendor, SpamPower. Group-IB found BraZetsu had remained fully undetected (FUD) by every VirusTotal engine two months after the initial samples were collected.
Group-IB assesses with high confidence that BraZetsu shares a codebase, build methodology, and infrastructure with the previously documented agenteV2 stealer/backdoor: both are Nuitka-compiled, both implement an identical WebSocket backdoor and Pastebin C2 pattern, and both share loader filenames. Independent research corroborates this overlap directly — ANY.RUN's agenteV2 writeup documents the real C2 server at 38.242.246.176:8443, the exact IP Group-IB lists as the Infected Marketplace's Contabo hosting address, giving a first-party infrastructure link between the two campaigns rather than a name-only association. BraZetsu's distribution domain caixaentradas1inboxshop[.]site is also used to deliver the unrelated-lineage Ousaban banking trojan, and BraZetsu overlaps in CNAB-targeting logic and ERP directory paths with the separately disclosed CNABHunter fraud tool, though Group-IB treats CNABHunter as an autonomous fraud tool rather than the same IAB framework.
Initial access is believed to rely on social engineering — VBS script downloaders masquerading as legal notifications ("processo de intimação") and loaders disguised as legitimate software (e.g., a fake Microsoft Edge update, msedge04.exe) — rather than a software vulnerability; no CVE is associated with this threat. Persistence is established via a "MonitorSystem" registry Run key. Portuguese-language log strings with natural idiom, plus extensive emoji-laden logging, support both native-speaker attribution and Group-IB's assessment that LLM-generated code contributed to the framework. Targeting has concentrated on Brazil, expanding to the Iberian Peninsula (Spain, Portugal) and Latin America (Argentina, Mexico, Chile, Paraguay), with compromised U.S. hosts advertised on th
Target sectors: financial-services, banking, government administration, police - law enforcement, health, cryptocurrency, insurance, logistics, ecommerce, telecommunications-isp, information-technology, cloud-devops
Target regions: brazil, spain, portugal, argentina, mexico, chile, paraguay, united states of america
Timeline
- Group-IB identifies the earliest BraZetsu build (v1), providing basic remote access and Windows registry Run-key persistence (month-level precision only; exact day not disclosed).
- ANY.RUN documents the related agenteV2 banking-trojan framework, sharing BraZetsu's Nuitka compilation, WebSocket backdoor design, and the same Contabo-hosted C2 IP 38.242.246.176:8443 (month-level precision only).
- Compromised U.S. hosts are advertised on the Infected Marketplace, marking the first observed expansion beyond Brazil/Iberia/LatAm targeting (month-level precision only).
- FortiGuard Labs identifies an Ousaban banking-trojan campaign targeting Spain and Portugal, sharing BraZetsu's caixaentradas1inboxshop.site distribution domain (month-level precision only).
- The related CNAB-targeting fraud tool CNABHunter is publicly disclosed, overlapping with BraZetsu in CNAB240/CNAB400 file targeting and ERP directory paths.
- BraZetsu evolves into its v5 build, an 'AI-enhanced intelligence-gathering platform' adding AI-assisted victim-value triage logic (month-level precision only).
- Group-IB publishes the BraZetsu / Exilware / Infected Marketplace research; the malware remains fully undetected (FUD) by all VirusTotal engines at time of publication.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1204.002, T1059.001, T1059.003, T1547.001, T1027.002, T1564.003, T1552.004, T1012, T1518, T1082