AI Malware Sells Access to Hacked Corporate Networks
Key Takeaways A new Windows malware framework, BraZetsu, is being used by the Brazilian threat actor Exilware to monetize corporate network access. BraZetsu performs extensive reconnaissance, mapping...
Key Takeaways
- A new Windows malware framework, BraZetsu, is being used by the Brazilian threat actor Exilware to monetize corporate network access.
- BraZetsu performs extensive reconnaissance, mapping victim systems, identifying valuable data, and assessing the “worth” of compromised machines for resale.
- The malware is written in Python, compiled into Windows executables, and employs a modular design, stealthy operations, and an interactive WebSocket connection to its command-and-control infrastructure.
- Researchers suspect the use of generative AI in BraZetsu’s development and potentially a server-side AI component for processing stolen information and ranking compromised systems.
- The compromised network access is sold on Exilware’s “Infect Marketplace,” fueling further criminal activities like fraud, data theft, and ransomware.
A sophisticated new Windows malware framework, dubbed BraZetsu, is enabling cybercriminals to transform initial corporate network intrusions into a lucrative marketplace for illicit access. This tool meticulously profiles victim systems, identifying critical business data, and then assigns a monetary value to the compromised foothold, streamlining the sale of access to other malicious actors.
Table Of Content
The primary targets of this campaign are organizations located in Brazil, the Iberian Peninsula, and broader Latin America. The malware typically infiltrates systems through social engineering tactics, often disguised as legitimate software updates or official notifications. Once executed, BraZetsu establishes a persistent communication channel, allowing its operators to conduct in-depth reconnaissance and deploy additional malicious payloads.
Cybersecurity firm Group-IB said in a report that their analysts have attributed BraZetsu with high confidence to a Brazilian threat actor known as Exilware. Initially, Exilware operated a basic remote-access tool, but this has evolved into a comprehensive framework specifically designed to support the operations of initial access brokers (IABs). This transformation highlights a growing trend where specialized malware facilitates a criminal supply chain for follow-on attacks, including ransomware and data exfiltration.
BraZetsu’s Advanced Capabilities
BraZetsu, engineered in Python and compiled into Windows executables, bypasses conventional signature-based detection mechanisms, making it a formidable threat. Group-IB’s analysis of recent samples revealed a modular architecture, techniques to conceal console activity, and the establishment of an interactive WebSocket connection with its command-and-control (C2) infrastructure.
The malware’s most notable feature is its advanced reconnaissance capability. It systematically inventories the infected device, cataloging running applications, open network ports, and software critical to business operations. Furthermore, BraZetsu delves into browser histories and financial remittance files, specifically targeting formats like Brazil’s CNAB. It also actively seeks out digital certificates and indicators of enterprise resource planning (ERP), industrial control systems (ICS), development environments, backup solutions, and security infrastructure.
Comprising 27 distinct functions, the majority of BraZetsu’s code is dedicated to identifying and detailing high-value systems. It possesses the ability to capture screenshots and execute commands remotely, offering operators both automated intelligence gathering and the flexibility of direct control. This blend of automation and manual intervention echoes the broader concerns surrounding AI-driven malware operations, where machine-assisted tools can significantly accelerate decision-making post-compromise. Group-IB noted that verbose logging and the presence of emoji-laden messages within the code suggest extensive use of generative AI during the malware’s development.
Critically, embedded strings within BraZetsu’s code imply the existence of a server-side AI component. This component is believed to process collected information, prioritize files based on their perceived value, and assess hardware and machine specifics. While researchers could not fully ascertain the complete scope of AI integration across the attack lifecycle, this capability fundamentally alters the economics of network intrusion. Instead of manually sifting through every compromised machine, criminals can leverage AI to automatically categorize and rank systems, enabling them to sell more thoroughly prepared and valuable access to buyers. This development underscores the necessity for defenders to treat unusual discovery activities with the same urgency as direct data theft attempts.
The Infect Marketplace and Expanding Risk
The threat actor Exilware has been operating an underground service called the “Infect Marketplace” since February 2026, where it sells access to compromised hosts. Group-IB believes that BraZetsu is the primary mechanism continuously replenishing this inventory. Buyers on the marketplace can acquire access and then deploy their own secondary malware, effectively compartmentalizing the initial breach from the subsequent attack. This model mirrors the illicit trade of brokered network access, which provides ransomware groups and other malicious actors with pre-established entry points into corporate networks.
The reported entry cost for access on the Infect Marketplace was approximately $5.80, significantly lowering the barrier for entry for other criminals. To manage demand, operators later imposed restrictions, requiring customers to spend deposited funds within 24 hours on peak days or 49 hours on normal days. While the operation has historically focused on Brazil and the surrounding regions, the appearance of two United States hosts advertised in April suggests a potential geographical expansion, though this alone does not confirm a permanent shift in targeting.
For cybersecurity defenders, this evolving threat model means an initial infection is merely the first stage. A compromised company could be meticulously profiled, then resold to a new buyer with entirely different malicious objectives. The increasing sophistication of these access broker operations necessitates a proactive and adaptive defense strategy.
What You Should Do
- Implement robust logging and monitoring on all endpoints, particularly those connected to financial and business-management systems.
- Segment critical assets within your network to limit lateral movement in the event of a compromise.
- Actively investigate suspicious registry queries, software enumeration activities, and searches for specific file types such as .cnab, .240, .400, .pfx, and .p12.
- Monitor for and investigate unusual WebSocket traffic directed to unfamiliar external destinations.
- Block or strictly control access to services like Pastebin when they are not essential for business operations, as BraZetsu utilizes them for retrieving encrypted C2 configuration data.
- Educate employees on the dangers of social engineering and the importance of verifying the legitimacy of unexpected software or notification files before opening them. Phishing remains a primary vector for initial access.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps://pastebin[.]com/raw/aF0WCxia |
Pastebin dead-drop resolver used to retrieve encrypted C2 configuration |
| URL | hxxps://pastebin[.]com/raw/hM0nXNBP |
Pastebin dead-drop resolver used to retrieve encrypted C2 configuration |
| URL | hxxps://pastebin[.]com/raw/9ChwVzzw |
Pastebin dead-drop resolver used to retrieve encrypted C2 configuration |
| Domain | c2[.]installscenter[.]com |
BraZetsu command-and-control infrastructure |
| Domain | infectonline[.]store |
Infrastructure associated with the operation |
| Domain | infect[.]online |
Infect Marketplace domain |
| IP address | 38[.]242[.]246[.]176 |
Previously observed infrastructure linked to the Infect Marketplace |
| File name | wifi_driver.exe |
BraZetsu loader name observed in the campaign |
| File name pattern | msedge[0-9].exe |
Loader naming pattern used to masquerade as Microsoft Edge |
| File name | msedge04.exe |
Observed BraZetsu loader filename |
| File name | agenteV2_historico_detect.dll |
AgenteV2 payload assessed as functionally equivalent to BraZetsu payload |
| File name | temp_agente.dll |
BraZetsu payload identified by Group-IB |
| SHA-256 | f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 |
BraZetsu-associated file hash |
| SHA-256 | 54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 |
BraZetsu-associated file hash |
| SHA-256 | 91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 |
BraZetsu-associated file hash |
| SHA-256 | cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 |
BraZetsu-associated file hash |
| SHA-256 | d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 |
BraZetsu-associated file hash |
| SHA-256 | 0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf |
BraZetsu-associated file hash |
| SHA-256 | 1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 |
BraZetsu-associated file hash |
| SHA-256 | 96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 |
BraZetsu-associated file hash |
| SHA-256 | 0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d |
BraZetsu-associated file hash |
| SHA-256 | 30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe |
BraZetsu-associated file hash |
| SHA-256 | 10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c |
BraZetsu-associated file hash |
| SHA-256 | bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8 |
BraZetsu-associated file hash |
| SHA-256 | 93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88 |
BraZetsu-associated file hash |
| SHA-256 | 67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2 |
BraZetsu-associated file hash |
| SHA-256 | c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138 |
BraZetsu-associated file hash |
| SHA-256 | 3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa |
BraZetsu-associated file hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.