Extraction of BraZetsu malware’s internal functions | Image: Group-IB
At a glance
- Actor or group: Exilware
- Activity type: Initial Access Broker (IAB) malware, reconnaissance
- Targets or victims: Iberian and LATAM corporate, financial, and industrial systems
- Scale: Unconfirmed number of regional victims; initial access sales start at $5.80
- Jurisdiction or law-enforcement status: Suspected Brazilian threat actor
- Source: Group-IB Threat Intelligence
TL;DR
Group-IB analysts discovered the BraZetsu malware framework operations in the wild. This Python-based initial access tool aggressively maps compromised networks to find high-value financial assets. A suspected Brazilian threat actor known as Exilware allegedly sells these compromised machines on an underground marketplace.
What Happened
Group-IB recently identified the BraZetsu malware framework targeting Latin American organizations. This specialized tool empowers Initial Access Brokers by transforming infected hosts into valuable commercial assets. The framework uses a modular architecture and advanced stealth techniques. In fact, at the time of the analysis, some malicious samples remained completely undetectable on standard antivirus engines like VirusTotal.
The malware conducts deep reconnaissance on infected machines immediately after deployment. It specifically searches for standardized financial remittance files, such as the Brazilian CNAB format used by local banks. Additionally, the tool extracts detailed browser histories from Chromium-based applications to map victim activity. The developers integrated artificial intelligence to process this stolen data. According to the report, “The framework’s codebase and operational logs indicate heavy reliance on generative AI, not only for development but potentially also for backend data triage and target prioritization.”
Bypassing Security Controls
BraZetsu retrieves encrypted configuration files from remote Pastebin URLs to establish a hidden connection. The malware explicitly checks for the presence of local enterprise security systems and endpoint detection tools. It flags the presence of specific antivirus products to help the operator gauge the value of the host. Furthermore, the framework evaluates hardware metadata to determine if the compromised machine is a priority target.
Overlaps with Other Malware
Interestingly, this malware shares a targeted directory list with another local fraud tool called CNABHunter. However, they rely on entirely distinct communication protocols and operational objectives. The developers likely copied the directory targeting from CNABHunter to upgrade their own reconnaissance capabilities. This rapid adaptation highlights the agile nature of modern cybercriminal development cycles.
Who Is Behind It
Security researchers attribute these BraZetsu malware framework operations to a Brazilian threat actor known as Exilware. Group-IB established this attribution with high confidence due to extensive infrastructure overlaps. Exilware manages a commercial platform called the Infected Marketplace, which is also known locally as Banco de Infects. This platform sells initial access to compromised systems directly to other criminals.
Social Engineering Delivery
The malware distribution likely relies heavily on localized social engineering tactics. Attackers often disguise the initial payload as a judicial summons or a critical Microsoft Edge browser update. These fake notices trick users into executing Visual Basic Script files that download the next stage of the attack.
Controlled Marketplace Rules
Exilware operates this cybercriminal ecosystem with highly specific access rules for buyers. For example, buyers must spend their deposited funds within 24 to 49 hours, depending on the volume of new infections. This strictly controlled approach reduces overall operational risk. Moreover, it limits the platform’s visibility to law enforcement agencies and security researchers.
Impact or Scale
This cybercriminal enterprise threatens critical infrastructure and corporate networks across the Iberian and LATAM regions. The threat actor focuses intensely on e-commerce platforms, ERP systems, and financial software. Researchers noted explicit scanning for industry standards like SAP, TOTVS, FactoryTalk, and Winbox.
Financial Toll
The precise number of compromised systems remains an unconfirmed claim. However, the marketplace offers initial access for as little as $5.80 per host. This incredibly low financial barrier allows various malicious actors to buy network access easily. After purchasing a host, the buyers can remotely deploy secondary payloads, such as ransomware or data exfiltration tools.
Expanding Geographic Focus
While primarily focused on Latin America, the operation might be expanding its footprint. In April 2026, the marketplace openly advertised two compromised systems located in the United States. This expansion suggests that the threat actor relies on a restricted network of partners to distribute the malware globally.
What Comes Next and How Readers Can Stay Protected
Defenders face a complex challenge due to this AI-enhanced IAB marketplace. Organizations must assume that initial access tools now perform highly targeted business profiling. Security teams should closely monitor for unusual access patterns near ERP file directories and sensitive financial data.
Hardening Defenses
Administrators must secure their endpoint detection tools and review their internal network segmentation. They should also train employees to recognize localized social engineering lures, such as fake legal notices or urgent software updates.
Threat Intelligence Sharing
Threat intelligence sharing is critical to identifying new command-and-control domains before an attack escalates. Security teams must track emerging indicators of compromise and apply them directly to their network defenses. Ultimately, companies need to treat every suspicious login as a potential stepping stone for a larger financial attack.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!