Zero Day Room
Live
Threats

BraZetsu Malware Fuels Criminal Access Marketplace

Group-IB researchers detail the BraZetsu malware framework, used by the Exilware group to compromise Windows hosts and sell access on an underground

Group-IB researchers detail the BraZetsu malware framework, used by the Exilware group to compromise Windows hosts and...

A sophisticated Python-based malware framework called BraZetsu is being used to turn compromised Windows systems into inventory for a criminal access marketplace. The Singapore-based cybersecurity firm Group-IB disclosed the threat, which is operated by a Portuguese-speaking actor tracked as Exilware and primarily targets organizations in Iberian and Latin America.

Julio Guapo Menezes and Miguel Salazar, malware analysts at Group-IB, described the framework as a comprehensive master toolkit. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that let Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets," they said. The framework's modular architecture and stealth techniques allowed some samples to evade detection on VirusTotal during analysis.

The malware's name is a portmanteau of "Brazil" and "Zetsu," a shadowy character from the Naruto manga. It first emerged in February 2026 and has evolved from a basic remote access trojan into an AI-enhanced intelligence-gathering framework. The core of the operation is the Infected Marketplace, also known as "Banco de Infects," where initial access to compromised hosts is sold for an initial deposit of roughly $5.80.

Marketplace and Monetization

The Infected Marketplace operates as an access-as-a-service platform. Criminal customers can purchase entry points into victims' systems and then remotely execute secondary malicious payloads via a specialized platform feature. This model creates a persistent threat-multiplier effect, allowing buyers to deploy their own tools without establishing the initial foothold.

Group-IB researchers noted the platform's service-enabled nature. "By functioning as a service-enabled platform, the marketplace allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect across the regional ecosystem," they stated. The framework catalogs compromised systems as tradable assets for these secondary actors.

Capabilities and Data Theft

BraZetsu is equipped for deep reconnaissance and data extraction. It uses generative AI to triage stolen data and prioritize high-value targets for the initial access brokers. The malware collects digital certificates, detailed browser histories from multiple browsers, and tracks user behavior through screen captures.

A key function is hunting for corporate financial remittance files, specifically those in the Brazilian CNAB format. This fixed-width text standard is used for electronic data interchange of financial transactions between companies and banks in Brazil. The malware shares functional overlap with a separate tool called CNABHunter, which systemically scans for, parses, and can even rewrite these financial files to redirect payments.

The framework relies on the WebSocket protocol to maintain persistent communication with the criminal marketplace command-and-control infrastructure.

Delivery and Evolution

The exact initial delivery method for BraZetsu remains unclear, though social engineering is suspected. The attack chain begins with a loader masquerading as Microsoft Edge, downloaded from a specific distribution domain. This domain has also been used to deliver the Ousaban banking trojan via phishing campaigns targeting users in Spain and Portugal.

The malware uses a Pastebin URL to extract its command-and-control information. It incorporates functions to obtain active application window titles, enumerate system details, run shell commands, capture screenshots, and locate common Enterprise Resource Planning software directories.

Researchers have identified five distinct versions of the malware in the wild. The third generation notably narrowed its operational focus to corporate targets in Brazil, though the threat actor was simultaneously observed advertising access to compromised hosts in the United States.

Connections and Attribution

Group-IB has linked BraZetsu with high confidence to another Python-based backdoor called AgenteV2, based on shared code, tradecraft, and infrastructure. AgenteV2 has previously targeted Brazilian users via phishing lures impersonating judicial summons and is engineered to stream a victim's screen in real-time to help fraud.

The assessment indicates both are part of the same initial access malware framework operated by Exilware. The malware's AI-driven capabilities automatically evaluate a compromised machine's commercial potential through hardware profiling and network mapping, allowing the group to categorize and price access based on the victim's perceived value. Recent versions show an exclusive focus on Brazilian infrastructure while maintaining capabilities for potential regional expansion across Latin America.

Related coverage

More from Threats