Infected Marketplace is a financially motivated initial access brokerage operation that sells access to Windows machines compromised through BraZetsu. BraZetsu is a Python-based framework compiled with Nuitka and attributed with high confidence to the Brazilian threat actor Exilware. Infected Marketplace inventories compromised systems and packages their characteristics into listings for prospective buyers, charging a deposit to browse the marketplace. Purchased access can facilitate subsequent ransomware deployment or financial fraud; these downstream activities are distinct from the marketplace's access-brokerage role. BraZetsu checks compromised systems for enterprise resource planning software, SCADA traces, endpoint detection and response products, and certificate files. Its operators have migrated command-and-control infrastructure between hosting providers while retaining recognizable naming conventions and Hestia Control Panel configurations. Multiple malware versions and infrastructure changes demonstrate continued development and operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates BraZetsu to identify Windows machines with ERP software, SCADA systems, and EDR products, and sells compromised access to other threat actors. Its infrastructure evolved before public indicators were published, while retaining recognizable hostname conventions and control-panel configurations. Ransomware deployment and financial fraud are attributed to access buyers, not explicitly to Infected Marketplace itself.
The group behind the BraZetsu initial-access brokerage operation. It sells access to already-compromised Windows machines and charges approximately 5.80 Brazilian reais for buyers to browse listings. Buyers may subsequently deploy ransomware or conduct financial theft; the article does not attribute those downstream actions to Infected Marketplace itself. Infrastructure tracking revealed migration between hosting providers while retaining recognizable control-panel and C2 naming and TLS patterns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.