AI-Powered BraZetsu Malware Turns Compromised Corporate PCs Into Tradable Assets

Group-IB has uncovered BraZetsu, a Python-based Windows malware framework designed to help cybercriminals gain, evaluate, and sell access to compromised corporate systems.

The malware is linked with high confidence to the Brazilian threat actor Exilware and functions as the technical engine behind an underground “Infected Marketplace.”

Unlike a conventional infostealer, BraZetsu is built primarily for initial access operations and intelligence gathering. It profiles infected computers, identifies valuable business applications and data, and sends the collected intelligence to attackers.

This allows criminals to determine which compromised machines have the highest commercial value. The malware has targeted organizations across Brazil and other Iberian and Latin American regions.

Its reconnaissance covers financial institutions, ERP platforms, e-commerce systems, industrial environments, government networks, healthcare systems, cryptocurrency services, and IT infrastructure.

BraZetsu has evolved through at least five versions since February 2026. Earlier versions provided basic remote access, while newer releases added deeper system profiling, financial-file discovery, browser-history collection, certificate theft, and automated victim classification.

BraZetsu AI Malware Markets

One of BraZetsu’s most notable characteristics is its apparent use of generative AI. Group-IB found extensive logging messages, emojis, and code structures that suggest AI-assisted development.

More importantly, malware strings indicate that an AI engine on the backend may process stolen information and help determine whether files or compromised systems should receive priority.

BraZetsu loader masquerading as a Microsoft Edge browser (Source: group-ib)
BraZetsu loader masquerading as a Microsoft Edge browser (Source: group-ib)

BraZetsu performs numerous checks to identify valuable environments. It searches for applications and indicators associated with SAP, TOTVS, Senior, Warsaw, Diebold, SCADA platforms, Veeam, Docker, VPN software, healthcare systems, e-commerce platforms, and other enterprise technologies.

The malware also examines Chromium-based browser profiles, including Chrome, Edge, Brave, Vivaldi, and Opera. Instead of focusing mainly on passwords and cookies, it extracts browser history to understand the victim’s activities and identify potentially valuable targets.

It can collect system information, enumerate processes and installed software, capture screenshots, execute Windows shell commands, and search for sensitive financial files such as CNAB, .240, and .400 files. It also searches for digital certificates with .PFX and .P12 extensions.

Extraction of BraZetsu malware’s internal functions (Source: group-ib)
Extraction of BraZetsu malware’s internal functions (Source: group-ib)

BraZetsu establishes communication with its command-and-control infrastructure through a persistent WebSocket connection. Its configuration can be retrieved from Pastebin and decoded using Base64 and XOR-based obfuscation.

The malware is closely connected to Exilware’s Infected Marketplace, where compromised systems are offered as commercial assets. Criminal customers can purchase access and potentially deploy their own malicious payloads onto the acquired machines.

Group-IB also identified infrastructure overlap between BraZetsu and the previously observed AgenteV2 malware, including shared filenames, Python/Nuitka compilation techniques, functionality, C2 infrastructure, and Pastebin-based configuration retrieval.

Indicators of Compromise (IOCs)

TypeIndicator
C2 Domainc2[.]installscenter[.]com
Domaininfectonline[.]store

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories