BraZetsu is a modular Python-based remote-access malware framework targeting Windows, compiled into native executables with Nuitka. It is attributed with high confidence to the Brazilian cybercriminal actor Exilware and supports initial-access brokering through the Infect Marketplace, also known as Infected Marketplace or Banco de Infects. The framework profiles compromised systems for resale, allowing buyers to execute additional tools and malware. BraZetsu and AgenteV2 are assessed with high confidence to be the same framework. Five generations were identified between February and May 2026, evolving from basic remote access into extensive automated host profiling.
BraZetsu enumerates system information, installed applications, processes, network services, recently accessed files, and active window titles. It identifies banking, ERP, e-commerce, industrial-control, backup, development, and endpoint-security environments. It collects Chromium-based browser histories, searches for Brazilian CNAB financial-remittance files, and steals digital certificates, transmitting collected material and host dossiers to its operators. Interactive capabilities include arbitrary shell-command execution, screenshot capture, and deployment of supplementary modules or payloads. Early versions established persistence through Windows Registry Run keys. Console concealment, configuration obfuscation, and compiled Python executables support defense evasion.
The framework retrieves Base64-encoded, XOR-obfuscated command-and-control configuration through Pastebin dead drops and maintains bidirectional WebSocket communications over TLS. This configuration mechanism permits infrastructure changes without rebuilding deployed malware. Its principal focus is Brazilian corporate environments, including financial, enterprise, industrial, and e-commerce systems, with broader activity associated with Latin America and Iberia. The exact initial infection mechanism remains unestablished; observed distribution components masqueraded as legitimate software or drivers, and associated scripts impersonated Portuguese-language legal notifications. BraZetsu primarily prepares compromised access for monetization rather than directly manipulating financial transactions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BraZetsu, an initial access broker tool, targets Windows machines, specifically looking for ERP software, SCADA systems, and EDR products.
BraZetsu is an initial access broker tool that breaks into Windows machines, checks them for ERP software, SCADA traces, EDR products, and certificate files, then packages the information for sale.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution / Persistence Interpreter / Run key T1059 / T1547.001
The TTP list explicitly identifies T1059.001 — Command and Scripting Interpreter: PowerShell.
The run_shell_commands function executes arbitrary commands through the Windows Command Shell (cmd.exe).
get_server_config() fetches a Pastebin blob, Base64-decodes it and XOR-decrypts with p4st3_s3cr3t_k3y.
Langage : Python 3, compilé avec Nuitka en exécutables PE natifs; the TTP list identifies T1027.002 — Software Packing.
It queries Windows uninstall registry locations to enumerate installed applications.
BraZetsu collects ... network-related information ... [and checks] ports ... and other indicators.
It ... examines active processes ... The checks include ... processes associated with SAP, TOTVS, Warsaw, and other financial software.
BraZetsu collects basic host information including the username, hostname, operating system version ... and network-related information.
BraZetsu searches recursively for .PFX and .P12 digital certificate files within user profiles and OneDrive locations. The framework searches for CNAB files.
Récupération de configuration : dead-drop via Pastebin (Base64 + XOR avec clé p4st3_s3cr3t_k3y).
C2 is not hardcoded in the binary. get_server_config() fetches a Pastebin blob.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targets Windows machines and identifies ERP software, SCADA systems, and EDR products. Its operators sell access to compromised machines for subsequent ransomware deployment or financial fraud. Analysis of its C2 infrastructure identified server, certificate, and hosting-provider changes, while persistent hostname conventions and control-panel configurations provided more stable detection signals than IP addresses or file hashes.
A Python framework compiled with Nuitka that compromises Windows machines and inventories installed enterprise software, industrial-control traces, security products, and certificate files. Compromised systems are offered through Infected Marketplace for buyers to exploit subsequently. Hunt.io traced infrastructure migrations using TLS certificates, persistent hostname conventions, and control-panel configurations across hosting providers, showing that these patterns outlasted individual IP addresses and binary hashes.
Python framework for Windows compiled with Nuitka, attributed by the cited reporting to Exilware with high confidence. It inventories compromised hosts for an access marketplace, profiling enterprise software, SCADA traces, EDR, browser data, digital certificates and CNAB files. Its C2 configuration comes from a Base64-encoded, XOR-encrypted Pastebin dead-drop, and its live channel uses WebSocket over TLS. Early versions persisted through the MonitorSystem Run key. Five versions appeared between February and May 2026. This infrastructure hunt identified a second VPS hosting panel and C2 certificates, with medium-confidence continuity between the two hosting environments; it did not independently validate attribution or observe agent traffic.
Python-based Windows IAB malware framework that profiles compromised hosts for financial, enterprise, government, industrial, cloud, and infrastructure value. It collects system, process, browser-history, financial-file, certificate, and network intelligence; supports screenshot capture and arbitrary cmd.exe command execution; uses Pastebin-hosted encrypted configuration and a TLS WebSocket backdoor; and can deploy supplementary payloads. It is used to supply profiled compromised access to Exilware’s Infect Marketplace.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.