HackMyIP
← Back to News
2026-09-03 The Hacker News

BraZetsu Malware: Windows Hosts Sold on Criminal Access Marketplace

MalwareAI ThreatsThreat Intel

Cybersecurity researchers at Group-IB have disclosed a sophisticated Python-based Windows malware framework called BraZetsu that converts compromised hosts into inventory on an underground criminal marketplace. Tracked to a threat group named Exilware—believed to be native Portuguese speakers—the toolkit is named after Brazil and the shadowy Naruto character Zetsu, reflecting its stealthy approach to infiltrating target networks. Analysts Julio Guapo Menezes and Miguel Salazar described BraZetsu as a "comprehensive master toolkit" that empowers Initial Access Brokers (IABs) by transforming breached systems into commercially valuable assets, with some samples achieving zero detections on VirusTotal at the time of analysis.

The malware is primarily scoped to target Iberian and Latin American organizations across e-commerce, corporate, financial, industrial, and law enforcement sectors. BraZetsu harbors deep reconnaissance capabilities, can scan victim networks, parse Brazilian CNAB financial remittance files, and extract detailed browser histories to profile victim activity. Group-IB noted heavy use of generative artificial intelligence not only in malware development but also for backend data triage and target prioritization—a trend that is rapidly lowering the barrier to entry for sophisticated cybercriminal operations. Network defenders can validate their own perimeter posture by running a port scanner to confirm no unexpected services are exposed to the internet.

BraZetsu underpins the Infected Marketplace (also known as "Banco de Infects" at infect[.]online), where Exilware monetizes initial access to compromised hosts for an initial deposit of roughly $5.80. The platform functions as an access-as-a-service operation, allowing criminal customers to remotely execute secondary payloads on purchased systems without needing to establish their own footholds—creating a persistent threat-multiplier across the regional ecosystem. The actor was first identified on February 2, 2026, and rapidly evolved from a basic remote access trojan into its current AI-enhanced intelligence-gathering framework. Organizations concerned about leaked credentials surfacing on such marketplaces can verify exposure with an email breach checker, while those investigating suspicious domains referenced in IAB listings should perform a WHOIS lookup to trace registration details and infrastructure ties to known threat actors.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →