BraZetsu is a Python-based Windows initial-access-broker malware framework attributed with high confidence to the Brazilian cybercriminal actor Exilware. Also tracked as AgenteV2, it establishes persistent access to compromised hosts, conducts automated and interactive reconnaissance, and supplies victim access to Exilware’s Infect Marketplace for resale to other criminals. It has primarily targeted corporate, financial, e-commerce, industrial, government, and infrastructure environments in Brazil, Latin America, and Iberia.
BraZetsu is compiled with Nuitka and uses encrypted dead-drop configuration retrieval together with persistent WebSocket-over-TLS command-and-control communications. It inventories host, operating-system, application, process, network-service, recently accessed-file, and active-window information to identify commercially valuable victims. It specifically identifies indicators of ERP, banking, industrial-control, cloud, backup, development, and endpoint-security environments; profiles Chromium-based browser histories; searches for Brazilian CNAB financial-remittance files; and collects digital certificates. The framework supports remote Windows command-shell execution, screen capture, and launching supplementary worker payloads. Earlier variants established Registry Run-key persistence and concealed console activity. Observed delivery activity involved social-engineering lures masquerading as routine software, drivers, or Portuguese-language legal notifications, with script-based downloaders retrieving later infection stages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BraZetsu is a Python-based Windows malware framework attributed to the Brazilian threat actor Exilware. Designed to support Initial Access Broker operations, BraZetsu performs automated reconnaissance to identify and prioritize high-value compromised systems for monetization through Exilware’s Infect Marketplace.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
The TTP list explicitly identifies T1059.001 — Command and Scripting Interpreter: PowerShell.
The run_shell_commands function executes arbitrary commands through the Windows Command Shell (cmd.exe).
Langage : Python 3, compilé avec Nuitka en exécutables PE natifs; the TTP list identifies T1027.002 — Software Packing.
Distribution infrastructure used filenames including msedge[0-9].exe and wifi_driver.exe, which masquerade as legitimate software and drivers. Some scripts masqueraded as Portuguese-language legal notification processes.
«делает скриншоты и отслеживает активное в данный момент окно».
It queries Windows uninstall registry locations to enumerate installed applications.
BraZetsu collects ... network-related information ... [and checks] ports ... and other indicators.
«изучает переменные окружения, открытые порты и процессы».
It ... examines active processes ... The checks include ... processes associated with SAP, TOTVS, Warsaw, and other financial software.
BraZetsu collects basic host information including the username, hostname, operating system version ... and network-related information.
BraZetsu searches recursively for .PFX and .P12 digital certificate files within user profiles and OneDrive locations. The framework searches for CNAB files.
BraZetsu communicat[es] through an interactive WebSocket backdoor over TLS port 8443. The channel supports bidirectional communication.
Récupération de configuration : dead-drop via Pastebin (Base64 + XOR avec clé p4st3_s3cr3t_k3y).
The malware’s get_server_config() function retrieves an encrypted and Base64-encoded configuration from a specified Pastebin URL.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python-based Windows IAB malware framework that profiles compromised hosts for financial, enterprise, government, industrial, cloud, and infrastructure value. It collects system, process, browser-history, financial-file, certificate, and network intelligence; supports screenshot capture and arbitrary cmd.exe command execution; uses Pastebin-hosted encrypted configuration and a TLS WebSocket backdoor; and can deploy supplementary payloads. It is used to supply profiled compromised access to Exilware’s Infect Marketplace.
Framework malveillant Python/Nuitka servant à l'accès initial et au vol de données. Il maintient un C2 WebSocket chiffré sur TLS/8443, obtient sa configuration via des dead-drops Pastebin, établit une persistance via une clé Run, collecte des données de navigation, fichiers financiers CNAB, certificats PFX/P12 et informations de profilage de victimes, puis permet la capture d'écran et l'exécution distante de commandes shell. Ses opérateurs commercialisent des accès compromis via Infect Marketplace.
A Python-based initial-access, reconnaissance, and access-broker framework operated in connection with Exilware and Infected Marketplace. It profiles compromised Windows hosts; harvests digital certificates and browser history; captures screenshots and active-window data; enumerates environment variables, ports, processes, recently accessed files, and ERP-related directories; supports shell-command execution; and communicates with the marketplace over WebSocket. It is geared toward preparing and selling access to compromised systems rather than directly conducting financial fraud.
A modular Python-based Windows initial-access framework used to monetize compromised hosts through an access-as-a-service marketplace. It performs host and network reconnaissance, AI-assisted victim triage and valuation, browser-history and certificate collection, CNAB financial-file discovery, screenshots, command execution, and deployment of additional payloads or worker modules. Group-IB assessed with high confidence that AgenteV2 and BraZetsu are the same framework.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.