ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

BraZetsu linked to Infected Marketplace

Group-IB said the BraZetsu malware framework, attributed to Exilware, collected victim data, supported a marketplace for compromised hosts and was likely delivered through a social-engineering chain.

The Hacker News

Group-IB said BraZetsu was a Python-based Windows malware framework used by a threat actor it tracked as Exilware. It said the malware targeted Iberian and Latin American organisations, including e-commerce, corporate, financial, industrial and law enforcement environments, and collected browser histories, certificates, screenshots and CNAB files.

The company said BraZetsu formed the basis of the Infected Marketplace, also called Banco de Infects, where access to compromised hosts was sold for an initial deposit of about $5.80. It said buyers could then use the platform to run their own secondary payloads on those systems.

Group-IB said it first observed the modular malware in early May 2026, with the earliest sample dated 9 February 2026, and that five versions had been found. It also said the third version focused more narrowly on corporate targets in Brazil, while the operator advertised access to two compromised hosts in the US.

The researchers said the delivery route was not clear, but they judged social engineering to be the likeliest method. They pointed to a loader that presented itself as Microsoft Edge and was retrieved from caixaentradas1inboxshop[.]site, and said files from that domain included VBS scripts used in the next stage.

Group-IB said BraZetsu overlapped with CNABHunter, a Python tool that scanned directories for CNAB files and altered payment details, and with AgenteV2, a backdoor previously tied to Brazilian users. It said shared code, tradecraft, infrastructure and functions led it to assess that BraZetsu and AgenteV2 were the same framework.

Named in this story

People

Julio Guapo Menezes
co-authored the report as a malware analyst
Miguel Salazar
co-authored the report as a malware analyst

Companies

Group-IB
issued the technical report on BraZetsu
Fortinet FortiGuard Labs
reported an earlier phishing campaign linked to Ousaban

Organisations

Exilware
the threat actor name used for the operators behind BraZetsu

Products and systems

BraZetsu
the malware framework described in the report
Infected Marketplace
the platform that sold access to compromised hosts, also called Banco de Infects
CNABHunter
a Python tool that overlapped with BraZetsu
Microsoft Edge
was impersonated by the initial loader
Ousaban
a banking trojan delivered from the same domain
AgenteV2
a backdoor that Group-IB linked to the same framework

How the source tells it

The source read like a threat-intelligence brief, mixing alarm, novelty and certainty-by-inference around the malware's capability and reach.

  • alarm loaded threat vocabulary and worst-case consequences were used throughout
  • hype superlatives and capability claims were attached to the malware and its AI use
  • novelty first-seen dates and rapid versioning were used to stress newness
  • speculative certainty likely, believed and high-confidence inferences were presented as firm assessments