AI-Driven Malware Marks Exilwire's Underground Trade in Breached Hosts
BraZetsu framework turns compromised Windows machines into commercial inventory for Intermediary access brokers.
In a dark twist on e-commerce, a newly documented Windows malware framework dubbed BraZetsu is transforming breached systems into tradable commodities, marking a sophisticated evolution in the initial access broker ecosystem. According to a report by Group-IB researchers Julio Guapo Menezes and Miguel Salazar, BraZetsu is a master toolkit that empowers initial access brokers by turning compromised systems into highly valuable commercial assets, with some samples evading detection on VirusTotal at the time of analysis.
Leveraging AI for Intrusion
The framework, a portmanteau of "Brazil" and "Zetsu," a fictional character from the Japanese manga series Naruto, represents a threat actor's playbook to infiltrate networks stealthily. The operators, tracked as Exilware, are believed to be native Portuguese speakers. The malware is primarily scoped to target e-commerce, corporate, financial, industrial, law enforcement, and other environments in Iberia and Latin America. Group-IB noted heavy use of generative AI for malware development, backend data triage, and target prioritization, enabling the malware to conduct deep reconnaissance and scan victim networks.
BraZetsu is equipped to extract detailed browser histories to understand victim activity, and it specifically targets financial remittance files in the Brazilian CNAB format—a fixed-width text standard for financial transactions between companies and banks. It also tracks user behavior through screen captures, collecting digital certificates and browser histories from multiple browsers including Google Chrome, Microsoft Edge, Brave, Vivaldi, and Opera.
Monetizing Access on the "Infected Marketplace"
The malware forms the foundation for the Infected Marketplace, also known as "Banco de Infects" or "infect[.]online," where Exilware monetizes initial access to compromised hosts for an initial deposit of roughly $5.80. The threat actor was first discovered on February 2, 2026, and has rapidly evolved its toolset from a basic remote access trojan to the AI-enhanced intelligence-gathering framework it is today.
The marketplace operates as an access-as-a-service platform, allowing criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect across the regional ecosystem. As the researchers described, customers can deploy their own malware or tools without needing to establish the initial foothold themselves.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets."
— Julio Guapo Menezes and Miguel Salazar, malware analysts at Group-IB
Key Capabilities and Connections
BraZetsu, first seen in early May 2026, is a modular Python framework that catalogs compromised systems as tradable assets. It functions include scanning infected hosts to triage data and prioritize high-value targets, collecting digital certificates and financial files, locating corporate CNAB remittance files, and maintaining persistent communication via the WebSocket protocol. It also exhibits overlap with CNABHunter, a custom tool that scans for CNAB files and rewrites them to replace payment information with attacker-controlled banking details, PIX keys, or barcodes.
Group-IB noted that BraZetsu is more geared towards initial access rather than direct financial fraud, but it shares a directory list with CNABHunter, leading researchers to suspect the developers saw a profitable opportunity after CNABHunter was publicly disclosed by a researcher named @johnk3r on X. BraZetsu was discovered in the wild a day after that disclosure.
Delivery Via Social Engineering
Exactly how BraZetsu is delivered remains unclear, but social engineering is the most likely vector. The starting point is a loader that masquerades as Microsoft Edge, downloaded from a distribution domain named "caixaentradas1inboxshop[.]site." Analysis of files associated with the domain has uncovered Visual Basic Script (VBS) files responsible for downloading the next stage of the attack. The same domain has been used to deliver the Ousaban banking trojan, with Fortinet observing a phishing campaign targeting Iberian Peninsula users.
Fortinet described the phishing attack in a report published in July, detailing how a PDF tricks victims into visiting a malicious webpage that scans the user's environment. If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack. The final payload is an EXE file dropped and executed by the VBS script.
The VBS file retrieves a steganographic PNG image that mimics a PDF, extracting a ZIP file from the image to obtain the Ousaban DLL, which is then run via DLL sideloading or process injection.
Technical Overlaps and Evolution
BraZetsu also uses a Pastebin URL to extract command-and-control information, similar to Ousaban. It incorporates functions to obtain the active application window title, check for banking keywords, enumerate environment variables, ports, and processes, run shell commands, capture screenshots, fetch recently opened files, and locate Enterprise Resource Planning (ERP) installation directories.
Five distinct versions of the malware have been detected in the wild to date, with the earliest dating back to February 9, 2026. The third generation notably narrowed its focus to corporate targets in Brazil, while the threat actor has been observed advertising access to two compromised hosts in the U.S. around the same time.
Group-IB also identified an IP address ("38.242.246[.]176") linked to AgenteV2, a Python-based backdoor targeting Brazilian users via phishing lures impersonating judicial summons. Based on shared codebase, tradecraft, infrastructure, and functional capabilities, Group-IB assessed with high confidence that AgenteV2 and BraZetsu refer to the same initial access malware framework.
Regional Targeting and Strategic Positioning
BraZetsu is not alone in the region. Dark Caracal, a cyber espionage group linked to Lebanon's General Directorate of General Security, was attributed to a targeted intrusion on a communications organization in Venezuela in June 2026. That incident involved the deployment of GoCaracal, a Go-based framework, and an updated version of Bandook, as detailed by Arctic Wolf. In a separate finding, LevelBlue discovered that an operator linked to Blind Eagle had their own machine compromised by an information stealer, revealing insights into their operations, including RAT-building tools, phishing templates, and infrastructure records.
The Stakes for Targets and the Industry
BraZetsu's evolution signals a growing trend where AI and modular malware are commoditizing access to compromised systems. For businesses, the risk is compounded: infected hosts become inventory for other criminals, enabling secondary attacks beyond initial compromise. The focus on financial remittance files and corporate ERP systems suggests that financial institutions and enterprises are prime targets. The findings underscore the need for robust detection and response strategies, particularly in regions where such malware is prevalent.
Sources
- The Hacker News Original source
Continue Reading
French hospital fined €500,000 after breach exposes data of 727,000
CNIL fines Hôpital privé de la Loire for security failures that led to a breach exposing data of over 727,000 people.
RMM Phishing Campaign Zeroes In on US Targets
A phishing campaign spanning 46 countries uses fake documents to push RMM tools, with 45% of activity aimed at the US.
FBI Opens Probe Into License Data Sale
A dark web service is selling 153M+ driver's license images, prompting an FBI inquiry.