Exilware is a Brazilian, Portuguese-speaking financially motivated cybercriminal threat actor operating an initial-access-broker service known as Infect Marketplace, also called Banco de Infects. Active since at least February 2026, the group uses the BraZetsu Windows malware framework, assessed to be the same framework as AgenteV2, to establish and profile compromised systems and offer access to those systems to criminal buyers. Marketplace customers can deploy their own tools and secondary payloads on purchased hosts. BraZetsu is a Python-based framework compiled as native Windows executables. It performs broad host and network reconnaissance, including enumeration of operating-system and host details, processes, installed applications, network services, recently accessed files, browser activity, active window titles, and enterprise software. It identifies environments associated with banking, e-commerce, ERP, industrial control, cloud, development, backup, and endpoint-security products to assess the commercial value of access. The malware searches for Brazilian CNAB remittance files and digital certificates, captures screenshots, executes commands through the Windows command shell, and can deploy supplementary worker modules. It communicates interactively with operators using WebSocket-over-TLS command and control and uses dead-drop configuration retrieval to enable command-and-control changes without rebuilding the malware. Exilware activity has principally targeted Brazilian organizations and broader Latin American and Iberian victims, including corporate, financial, industrial, e-commerce, government, and law-enforcement environments. The operation has also offered compromised United States systems for sale. Observed delivery activity has involved social-engineering lures masquerading as legitimate software or Portuguese-language notifications. BraZetsu employs persistence, console concealment, compiled Python binaries, and configuration obfuscation to reduce detection and support sustained access-broker operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brazilian financially motivated initial-access-broker operator that develops and operates BraZetsu and the restricted Infect Marketplace ('Banco de Infects'). It automates reconnaissance and commercial valuation of compromised hosts, then sells access to customers capable of deploying follow-on payloads.
Brazilian cybercriminal operator of the Infect Marketplace/Banco de Infects initial-access marketplace. It develops and operates the BraZetsu/AgenteV2 Python-Nuitka framework to profile compromised hosts, steal browser, financial, certificate, and system data, and sell access to compromised machines. The framework includes server-side AI-assisted sorting and prioritization of stolen data.
A Portuguese-speaking cybercriminal group operating BraZetsu and the Infected Marketplace/Banco de Infects access-broker platform. It compromises Windows systems, performs reconnaissance and automated victim-value assessment, and offers access to infected hosts for sale to other criminals.
Operates an initial-access-broker and access-as-a-service marketplace, selling access to compromised systems through the Infected Marketplace. It uses the AI-enabled BraZetsu framework to profile, reconnoiter, categorize, and price victims, while enabling marketplace customers to deploy secondary payloads on purchased hosts. Recent activity is focused on Brazilian corporate infrastructure, with intended expansion across Latin America.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.