Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake AI Chatbots Steal Credentials, Target OpenAI, Anthropic Users
September 1, 2026
Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations
September 1, 2026
Critical Microsoft Teams Vulnerability Lets Attackers Impersonate Users
September 1, 2026
Home/CyberSecurity News/AI Malware Sells Access to Hacked Corporate Networks
CyberSecurity News

AI Malware Sells Access to Hacked Corporate Networks

Key Takeaways A new Windows malware framework, BraZetsu, is being used by the Brazilian threat actor Exilware to monetize corporate network access. BraZetsu performs extensive reconnaissance, mapping...

Sarah simpson
Sarah simpson
September 1, 2026 5 Min Read
3 0

Key Takeaways

  • A new Windows malware framework, BraZetsu, is being used by the Brazilian threat actor Exilware to monetize corporate network access.
  • BraZetsu performs extensive reconnaissance, mapping victim systems, identifying valuable data, and assessing the “worth” of compromised machines for resale.
  • The malware is written in Python, compiled into Windows executables, and employs a modular design, stealthy operations, and an interactive WebSocket connection to its command-and-control infrastructure.
  • Researchers suspect the use of generative AI in BraZetsu’s development and potentially a server-side AI component for processing stolen information and ranking compromised systems.
  • The compromised network access is sold on Exilware’s “Infect Marketplace,” fueling further criminal activities like fraud, data theft, and ransomware.

A sophisticated new Windows malware framework, dubbed BraZetsu, is enabling cybercriminals to transform initial corporate network intrusions into a lucrative marketplace for illicit access. This tool meticulously profiles victim systems, identifying critical business data, and then assigns a monetary value to the compromised foothold, streamlining the sale of access to other malicious actors.

Table Of Content

  • Key Takeaways
  • BraZetsu’s Advanced Capabilities
  • The Infect Marketplace and Expanding Risk
  • What You Should Do

The primary targets of this campaign are organizations located in Brazil, the Iberian Peninsula, and broader Latin America. The malware typically infiltrates systems through social engineering tactics, often disguised as legitimate software updates or official notifications. Once executed, BraZetsu establishes a persistent communication channel, allowing its operators to conduct in-depth reconnaissance and deploy additional malicious payloads.

Cybersecurity firm Group-IB said in a report that their analysts have attributed BraZetsu with high confidence to a Brazilian threat actor known as Exilware. Initially, Exilware operated a basic remote-access tool, but this has evolved into a comprehensive framework specifically designed to support the operations of initial access brokers (IABs). This transformation highlights a growing trend where specialized malware facilitates a criminal supply chain for follow-on attacks, including ransomware and data exfiltration.

BraZetsu’s Advanced Capabilities

BraZetsu, engineered in Python and compiled into Windows executables, bypasses conventional signature-based detection mechanisms, making it a formidable threat. Group-IB’s analysis of recent samples revealed a modular architecture, techniques to conceal console activity, and the establishment of an interactive WebSocket connection with its command-and-control (C2) infrastructure.

The malware’s most notable feature is its advanced reconnaissance capability. It systematically inventories the infected device, cataloging running applications, open network ports, and software critical to business operations. Furthermore, BraZetsu delves into browser histories and financial remittance files, specifically targeting formats like Brazil’s CNAB. It also actively seeks out digital certificates and indicators of enterprise resource planning (ERP), industrial control systems (ICS), development environments, backup solutions, and security infrastructure.

Comprising 27 distinct functions, the majority of BraZetsu’s code is dedicated to identifying and detailing high-value systems. It possesses the ability to capture screenshots and execute commands remotely, offering operators both automated intelligence gathering and the flexibility of direct control. This blend of automation and manual intervention echoes the broader concerns surrounding AI-driven malware operations, where machine-assisted tools can significantly accelerate decision-making post-compromise. Group-IB noted that verbose logging and the presence of emoji-laden messages within the code suggest extensive use of generative AI during the malware’s development.

Critically, embedded strings within BraZetsu’s code imply the existence of a server-side AI component. This component is believed to process collected information, prioritize files based on their perceived value, and assess hardware and machine specifics. While researchers could not fully ascertain the complete scope of AI integration across the attack lifecycle, this capability fundamentally alters the economics of network intrusion. Instead of manually sifting through every compromised machine, criminals can leverage AI to automatically categorize and rank systems, enabling them to sell more thoroughly prepared and valuable access to buyers. This development underscores the necessity for defenders to treat unusual discovery activities with the same urgency as direct data theft attempts.

The Infect Marketplace and Expanding Risk

The threat actor Exilware has been operating an underground service called the “Infect Marketplace” since February 2026, where it sells access to compromised hosts. Group-IB believes that BraZetsu is the primary mechanism continuously replenishing this inventory. Buyers on the marketplace can acquire access and then deploy their own secondary malware, effectively compartmentalizing the initial breach from the subsequent attack. This model mirrors the illicit trade of brokered network access, which provides ransomware groups and other malicious actors with pre-established entry points into corporate networks.

The reported entry cost for access on the Infect Marketplace was approximately $5.80, significantly lowering the barrier for entry for other criminals. To manage demand, operators later imposed restrictions, requiring customers to spend deposited funds within 24 hours on peak days or 49 hours on normal days. While the operation has historically focused on Brazil and the surrounding regions, the appearance of two United States hosts advertised in April suggests a potential geographical expansion, though this alone does not confirm a permanent shift in targeting.

For cybersecurity defenders, this evolving threat model means an initial infection is merely the first stage. A compromised company could be meticulously profiled, then resold to a new buyer with entirely different malicious objectives. The increasing sophistication of these access broker operations necessitates a proactive and adaptive defense strategy.

What You Should Do

  • Implement robust logging and monitoring on all endpoints, particularly those connected to financial and business-management systems.
  • Segment critical assets within your network to limit lateral movement in the event of a compromise.
  • Actively investigate suspicious registry queries, software enumeration activities, and searches for specific file types such as .cnab, .240, .400, .pfx, and .p12.
  • Monitor for and investigate unusual WebSocket traffic directed to unfamiliar external destinations.
  • Block or strictly control access to services like Pastebin when they are not essential for business operations, as BraZetsu utilizes them for retrieving encrypted C2 configuration data.
  • Educate employees on the dangers of social engineering and the importance of verifying the legitimacy of unexpected software or notification files before opening them. Phishing remains a primary vector for initial access.

Indicators of Compromise (IoCs):

Type Indicator Description
URL hxxps://pastebin[.]com/raw/aF0WCxia Pastebin dead-drop resolver used to retrieve encrypted C2 configuration
URL hxxps://pastebin[.]com/raw/hM0nXNBP Pastebin dead-drop resolver used to retrieve encrypted C2 configuration
URL hxxps://pastebin[.]com/raw/9ChwVzzw Pastebin dead-drop resolver used to retrieve encrypted C2 configuration
Domain c2[.]installscenter[.]com BraZetsu command-and-control infrastructure
Domain infectonline[.]store Infrastructure associated with the operation
Domain infect[.]online Infect Marketplace domain
IP address 38[.]242[.]246[.]176 Previously observed infrastructure linked to the Infect Marketplace
File name wifi_driver.exe BraZetsu loader name observed in the campaign
File name pattern msedge[0-9].exe Loader naming pattern used to masquerade as Microsoft Edge
File name msedge04.exe Observed BraZetsu loader filename
File name agenteV2_historico_detect.dll AgenteV2 payload assessed as functionally equivalent to BraZetsu payload
File name temp_agente.dll BraZetsu payload identified by Group-IB
SHA-256 f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 BraZetsu-associated file hash
SHA-256 54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 BraZetsu-associated file hash
SHA-256 91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 BraZetsu-associated file hash
SHA-256 cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 BraZetsu-associated file hash
SHA-256 d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 BraZetsu-associated file hash
SHA-256 0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf BraZetsu-associated file hash
SHA-256 1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 BraZetsu-associated file hash
SHA-256 96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 BraZetsu-associated file hash
SHA-256 0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d BraZetsu-associated file hash
SHA-256 30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe BraZetsu-associated file hash
SHA-256 10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c BraZetsu-associated file hash
SHA-256 bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8 BraZetsu-associated file hash
SHA-256 93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88 BraZetsu-associated file hash
SHA-256 67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2 BraZetsu-associated file hash
SHA-256 c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138 BraZetsu-associated file hash
SHA-256 3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa BraZetsu-associated file hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerMalwarephishingransomwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

WordPress AI Finds Security Flaws Before Exploitation

Next Post

Fake ChatGPT Sites Deliver Malware via Malvertising Campaign

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Fake ChatGPT Sites Deliver Malware via Malvertising Campaign
September 1, 2026
AI Malware Sells Access to Hacked Corporate Networks
September 1, 2026
WordPress AI Finds Security Flaws Before Exploitation
September 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us