BraZetsu Malware Ranks and Sells Access to Compromised PCs

A hacked computer has become a commodity whose value an algorithm determines by its banking software, corporate systems, and owner data. Group-IB specialists have discovered a malicious framework named BraZetsu, which supplies an underground marketplace with ready-made points of entry into organizations.
Linked to Exilware
Group-IB linked BraZetsu with high confidence to the Brazilian threat actor Exilware. The framework operates as an access broker tool: it entrenches itself in Windows, connects to the command server via WebSocket, and allows commands to be executed, screenshots to be taken, and additional malicious modules to be launched.
Profiling a Victim by Value
BraZetsu studies the infected environment and assigns the computer tags that help gauge its potential profitability. The malware searches for banking programs, ERP systems, security tools, cloud configurations, backups, and industrial software. Of particular interest are CNAB financial files, digital certificates, browser history, and information about the corporate network.
Signs of Generative AI
The code reveals indications of the active use of generative AI during development, including detailed logs and emoji. Strings inside BraZetsu also mention a server-side AI meant to sort stolen information and identify priority targets. Group-IB was unable to establish how widely such a mechanism is applied in real operations.
Five Versions and a Marketplace
Since February 2026, Group-IB has traced five versions of BraZetsu, from a simple remote-access tool to a platform for automated reconnaissance. Infected computers ended up on the Infect Marketplace, also known as Banco de Infects. A customer paid a minimum of 30 Brazilian reais, selected a suitable system, and could remotely upload their own malware onto it.
Delivery and Defence
The exact method of initial infection remains unknown. The discovered domains, VBS scripts, and files named msedge[0-9].exe and wifi_driver.exe point to social engineering and disguise as legitimate software. Group-IB advises monitoring for such names, unusual WebSocket connections, requests to Pastebin, searches for certificates and financial files, and separating critical systems from other network segments.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.