Description

?Security researchers have uncovered BraZetsu, a Python-based Windows malware framework designed to support an underground marketplace selling access to compromised systems. Rather than operating solely as a conventional information stealer, the malware performs extensive reconnaissance and collects data that can help Initial Access Brokers (IABs) assess the value of infected machines. Developed by the Portuguese-speaking threat actor Exilware, BraZetsu has primarily been observed targeting organizations across Brazil, Latin America, and the Iberian Peninsula, including financial, e-commerce, industrial, corporate, and law-enforcement environments. Its modular design enables collection of browser histories, digital certificates, screenshots, running processes, network information, recently accessed files, and financial documents. The framework can also identify Brazilian CNAB financial-remittance files and communicate persistently with its operators through WebSocket connections. BraZetsu reportedly powers an “Infected Marketplace,” where compromised hosts are offered to other criminals as purchasable access points, with prices starting at approximately $5.80. Customers can subsequently use the service to execute their own malicious payloads on acquired systems, effectively turning the malware into an access-as-a-service platform. Researchers identified similarities between BraZetsu and CNABHunter, another Python-based tool capable of locating and processing Brazilian banking files. While CNABHunter is associated more directly with payment manipulation and financial fraud, BraZetsu focuses on reconnaissance, initial access, remote command execution, and deployment of additional modules. Investigators believe its CNAB-related functionality may have been adopted after CNABHunter became publicly known. Multiple BraZetsu variants have been identified, with newer versions showing a stronger emphasis on Brazilian corporate infrastructure. The malware’s precise delivery mechanism remains uncertain, although social engineering and phishing are considered likely entry points. Researchers observed a loader disguised as Microsoft Edge and linked to infrastructure previously associated with the Ousaban banking trojan. BraZetsu also retrieves command-and-control information through Pastebin and includes capabilities for monitoring active applications, identifying banking-related activity, executing shell commands, capturing screenshots, and discovering enterprise software installations. Infrastructure and code similarities have additionally connected the framework to AgenteV2, a Python backdoor previously used against Brazilian targets. According to researchers, the combination of automated machine profiling, AI-assisted data assessment, and marketplace integration allows Exilware to identify and prioritize high-value victims while continuously replenishing its pool of compromised hosts for criminal customers.