Cybersecurity
BraZetsu linked to Infected Marketplace
Group-IB said the BraZetsu malware framework, attributed to Exilware, collected victim data, supported a marketplace for compromised hosts and was likely delivered through a social-engineering chain.
- Group-IB said BraZetsu was a Python-based Windows malware framework used by Exilware to support the Infected Marketplace.
- The company said the marketplace charged an initial deposit of roughly $5.80 for access to compromised hosts.
- Group-IB said it first saw BraZetsu in early May 2026, with the earliest sample dated 9 February 2026, and found five versions in the wild.
- The company said the malware targeted Iberian and Latin American organisations and collected browser histories, certificates, screenshots and CNAB files.
- Group-IB said delivery was unclear but likely began with a loader that posed as Microsoft Edge from caixaentradas1inboxshop[.]site, and it later linked BraZetsu with AgenteV2.
Group-IB said BraZetsu was a Python-based Windows malware framework used by a threat actor it tracked as Exilware. It said the malware targeted Iberian and Latin American organisations, including e-commerce, corporate, financial, industrial and law enforcement environments, and collected browser histories, certificates, screenshots and CNAB files.
The company said BraZetsu formed the basis of the Infected Marketplace, also called Banco de Infects, where access to compromised hosts was sold for an initial deposit of about $5.80. It said buyers could then use the platform to run their own secondary payloads on those systems.
Group-IB said it first observed the modular malware in early May 2026, with the earliest sample dated 9 February 2026, and that five versions had been found. It also said the third version focused more narrowly on corporate targets in Brazil, while the operator advertised access to two compromised hosts in the US.
The researchers said the delivery route was not clear, but they judged social engineering to be the likeliest method. They pointed to a loader that presented itself as Microsoft Edge and was retrieved from caixaentradas1inboxshop[.]site, and said files from that domain included VBS scripts used in the next stage.
Group-IB said BraZetsu overlapped with CNABHunter, a Python tool that scanned directories for CNAB files and altered payment details, and with AgenteV2, a backdoor previously tied to Brazilian users. It said shared code, tradecraft, infrastructure and functions led it to assess that BraZetsu and AgenteV2 were the same framework.
Named in this story
People
- Julio Guapo Menezes
- co-authored the report as a malware analyst
- Miguel Salazar
- co-authored the report as a malware analyst
Companies
- Group-IB
- issued the technical report on BraZetsu
- Fortinet FortiGuard Labs
- reported an earlier phishing campaign linked to Ousaban
Organisations
- Exilware
- the threat actor name used for the operators behind BraZetsu
Products and systems
- BraZetsu
- the malware framework described in the report
- Infected Marketplace
- the platform that sold access to compromised hosts, also called Banco de Infects
- CNABHunter
- a Python tool that overlapped with BraZetsu
- Microsoft Edge
- was impersonated by the initial loader
- Ousaban
- a banking trojan delivered from the same domain
- AgenteV2
- a backdoor that Group-IB linked to the same framework
How the source tells it
The source read like a threat-intelligence brief, mixing alarm, novelty and certainty-by-inference around the malware's capability and reach.
- alarm loaded threat vocabulary and worst-case consequences were used throughout
- hype superlatives and capability claims were attached to the malware and its AI use
- novelty first-seen dates and rapid versioning were used to stress newness
- speculative certainty likely, believed and high-confidence inferences were presented as firm assessments