BraZetsu Malware Ranks and Sells Access to Compromised PCs

BraZetsu malware profiling a compromised computer by value to feed an underground Initial Access Broker marketplace
BraZetsu loader masquerading as a Microsoft Edge browser

A hacked computer has become a commodity whose value an algorithm determines by its banking software, corporate systems, and owner data. Group-IB specialists have discovered a malicious framework named BraZetsu, which supplies an underground marketplace with ready-made points of entry into organizations.

Linked to Exilware

Group-IB linked BraZetsu with high confidence to the Brazilian threat actor Exilware. The framework operates as an access broker tool: it entrenches itself in Windows, connects to the command server via WebSocket, and allows commands to be executed, screenshots to be taken, and additional malicious modules to be launched.

Profiling a Victim by Value

BraZetsu studies the infected environment and assigns the computer tags that help gauge its potential profitability. The malware searches for banking programs, ERP systems, security tools, cloud configurations, backups, and industrial software. Of particular interest are CNAB financial files, digital certificates, browser history, and information about the corporate network.

Signs of Generative AI

The code reveals indications of the active use of generative AI during development, including detailed logs and emoji. Strings inside BraZetsu also mention a server-side AI meant to sort stolen information and identify priority targets. Group-IB was unable to establish how widely such a mechanism is applied in real operations.

Five Versions and a Marketplace

Since February 2026, Group-IB has traced five versions of BraZetsu, from a simple remote-access tool to a platform for automated reconnaissance. Infected computers ended up on the Infect Marketplace, also known as Banco de Infects. A customer paid a minimum of 30 Brazilian reais, selected a suitable system, and could remotely upload their own malware onto it.

Delivery and Defence

The exact method of initial infection remains unknown. The discovered domains, VBS scripts, and files named msedge[0-9].exe and wifi_driver.exe point to social engineering and disguise as legitimate software. Group-IB advises monitoring for such names, unusual WebSocket connections, requests to Pastebin, searches for certificates and financial files, and separating critical systems from other network segments.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply