BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.

“Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets,” Group-IB malware analysts Julio Guapo Menezes and Miguel Salazar said in a technical report.

“The framework exhibits high operational maturity, utilizing a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis.”

BraZetsu is a portmanteau of “Brazil” and “Zetsu,” a fictional character from the Japanese Manga series Naruto who is known to operate as a threat from the shadows. The naming is inspired by the fact that the initial access tool stealthily infiltrates target networks to conduct highly destructive follow-on attacks. The threat actors, tracked as Exilware, are believed to be native Portuguese speakers.

The Singapore-headquartered company said BraZetsu is primarily scoped to target Iberian and Latin American targets in e-commerce, corporate, financial, industrial, law enforcement, and other environments. Evidence points to heavy use of generative artificial intelligence (AI) for not just malware development, but also backend data triage and target prioritization.

The malware harbors capabilities to conduct deep reconnaissance and scan victim networks. For financial remittance files, such as those in the Brazilian CNAB format, a fixed-width text file standard used for electronic data interchange (EDI) of financial transactions between companies and banks in Brazil. It’s also equipped to extract detailed browser histories to get an understanding of victim activity.

BraZetsu forms the foundation for the Infected Marketplace (aka “Banco de Infects”, “infect[.]online”), a platform where the threat actor monetizes initial access to compromised hosts for an initial deposit of roughly $5.80. The threat actor was first discovered on February 2, 2026, rapidly evolving its toolset from a basic remote access trojan to the AI-enhanced intelligence-gathering framework it is today.

“By functioning as a service-enabled platform, the marketplace allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect across the regional ecosystem,” the researchers said.

“The marketplace functions as an access-as-a-service operation, in which other criminals can purchase entry points into victims’ systems. Once a criminal purchases access through the marketplace, they can deploy malicious payloads via a specialized platform feature. This allows buyers to remotely execute their own malware or tools on the compromised systems without needing to establish the initial foothold themselves.”

The modular Python framework, per Group-IB, was first seen in early May 2026, and offers a way for the operators to catalog compromised systems as “tradable assets” for secondary threat actors on the marketplace. It supports the following functions –

  • Scans infected hosts and uses generative AI to triage data and prioritize high-value targets for IABs
  • Collects digital certificates, browser histories from Google Chrome, Microsoft Edge, Brave, Vivaldi, and Opera, and financial files while tracking user behavior through screen captures
  • Attempts to locate corporate financial remittance files in the Brazilian Federation of Banks’ CNAB format
  • Relies on the WebSocket protocol to maintain persistent communication with the Infected Marketplace

BraZetsu also shares some level of overlap with CNABHunter, a custom Python tool that systemically scans local and network directories for CNAB files, parses financial transaction records, and exfiltrates payment metadata to a dedicated HTTP-based infrastructure. Furthermore, CNABHunter polls a remote server for operator-issued orders.

“When instructed, it automatically rewrites the original CNAB files by replacing legitimate payment information with attacker-controlled banking details, PIX keys, or barcodes,” Group-IB said. “This workflow is specifically designed to facilitate financial fraud against corporate payment processes.”

On the other hand, BraZetsu is more geared towards initial access rather than an implement for financial fraud. Besides performing broad host reconnaissance and gathering CNAB-related files, it facilitates autonomous data collection, interactive, hands-on operations through remote shell command execution, and the deployment of additional worker modules.

The core aspect that ties them together is the directory list used to locate CNAB-related files. It’s suspected that the developers associated with BraZetsu incorporated the same functionality after seeing a “profitable opportunity.” This assessment is based on the fact that BraZetsu was discovered in the wild a day after CNABHunter was publicly disclosed by a researcher named @johnk3r on X.

Exactly how this malware is delivered to victims remains unclear at this stage. However, social engineering is the most likely culprit. The starting point is a loader that masquerades as Microsoft Edge and is downloaded from a distribution domain named “caixaentradas1inboxshop[.]site.”

An analysis of the files associated with the domain has uncovered Visual Basic Script (VBS) files responsible for downloading the next stage of the attack. Interestingly, the same domain has been used to deliver the Ousaban banking trojan. In May 2026, Fortinet FortiGuard Labs said it identified an email phishing attack targeting users in the Iberian Peninsula with an MSI downloader that deploys Ousaban.

“The phishing PDF tricks victims into visiting a malicious webpage that scans the user’s environment,” Fortinet said in a report published in July. “If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack. The final payload is an EXE file that is dropped onto the victim’s computer and executed by the VBS script.”

The VBS file is designed to retrieve a steganographic PNG image that mimics a PDF document, which then extracts a ZIP file from the image and extracts from it the Ousaban DLL. The final payload is then run via DLL sideloading or process injection.

Like in the case of Ousaban, BraZetsu uses a Pastebin URL to extract the C2 information. It also incorporates dedicated functions to obtain the user’s active application window title and, if it contains common banking keywords; enumerate environment variables, network ports, and running processes; run shell commands; capture screenshots; fetch recently opened files; and locate common Enterprise Resource Planning (ERP) installation directories.

In all, five distinct versions of the malware have been detected in the wild to date, with the earliest iteration dating back to February 9, 2026. The third generation is notable for narrowing its operational focus to corporate targets in Brazil. That said, the threat actor has been observed advertising access to two compromised hosts located in the U.S. around the same time.

“BraZetsu functions as the primary malware framework supporting Exilware’s Initial Access Broker (IAB) operation by establishing initial footholds and continuously replenishing the Infect Marketplace inventory,” Group-IB said.

A deeper hunt for artifacts matching the naming convention used by Exilware has also identified an IP address (“38.242.246[.]176”) that has been previously tied to AgenteV2, a Python-based backdoor that has targeted Brazilian users via phishing lures impersonating judicial summons. The malware is engineered to stream a victim’s screen to the attacker in real-time to facilitate financial fraud as soon as a banking portal is launched.

Based on shared codebase, tradecraft, infrastructure, and functional capabilities, Group-IB has assessed with high confidence that both AgenteV2 and BraZetsu refer to the same initial access malware framework.

“The malware’s AI-driven assessment capabilities automatically evaluate compromised machines’ commercial potential through hardware profiling, software environment analysis, and network infrastructure mapping, enabling Exilware to categorize automatically and price marketplace access based on victim value,” the company said.

“Recent versions show an exclusive focus on Brazilian infrastructure while maintaining multi-language capabilities for regional expansion, indicating deep operational knowledge of the domestic threat landscape and strategic positioning for broader Latin American operations targeting critical infrastructure and high-value commercial sectors.”

BraZetsu is far from the only malware that has targeted Latin America. In recent weeks, Dark Caracal, a cyber espionage group with ties to Lebanon’s General Directorate of General Security, has been attributed to a targeted intrusion affecting a communications organization in Venezuela.

The incident, which took place in June 2026, resulted in the deployment of a previously undocumented Go-based modular framework codenamed GoCaracal and an updated version of Bandook. GoCaracal appears in two variants: a lightweight implant that establishes initial access and drops additional payloads, and an extended build for sustained intelligence collection and interactive control.

“The extended build also supports an Ethereum smart-contract fallback that allows operators to retrieve replacement command-and-control (C2) infrastructure without redeploying the malware,” ArcticWolf said. “These findings show that Dark Caracal is modernizing the malware and infrastructure behind its established operations and tradecraft.”

The delivery method is consistent with a previous campaign documented by Kaspersky in which the threat actor used invoice-themed lures containing SVG attachments to distribute a backdoor called AsioGate, a successor to Poco RAT, via a Delphi loader in attacks targeting users and entities in Chile and Brazil.

The findings also come as LevelBlue found that an operator linked to Blind Eagle had their own machine compromised by an information stealer, offering crucial insights into the campaign. Blind Eagle is a Spanish-speaking hacking group active since at least 2018, primarily targeting government agencies, financial institutions, and corporate entities in Latin America, particularly in Colombia and Ecuador.

“What we found on that machine provided a much broader picture of the operation: RAT-building tools, phishing templates, bulk-email software, infrastructure records, and evidence of repeated efforts to make malicious files harder for security software to detect,” security researcher Serhii Melnyk said.

“The machine appears to have been compromised by an unrelated commodity infostealer – the same general type of malware that Blind Eagle uses to steal information from victims. In other words, the trail began when an apparent attacker-side workstation was itself exposed by someone else’s malware.”

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.