Group-IB attributed the Python-based Windows framework BraZetsu—also tracked as AgenteV2—to the Brazilian threat actor Exilware with high confidence. Distributed through social-engineering lures posing as routine software or notifications, the malware establishes persistence and profiles compromised organizations, primarily in Brazil, Iberia, and Latin America. Exilware uses the resulting access to supply its Infect Marketplace, where compromised corporate hosts are offered for sale.
BraZetsu enumerates systems, networks, processes, registry entries, browsers, ERP and security products, and searches for financial remittance records such as CNAB files and PFX/P12 certificates. It can collect browser history, execute remote shell commands, capture screenshots, and deploy additional worker payloads; its encrypted configuration is retrieved from Pastebin and its C2 uses WebSockets over TLS. Researchers identified five versions between February and May 2026 and reported possible server-side AI-assisted prioritization of stolen data and victim value, though the extent of AI use remains unconfirmed. Defenders should investigate unusual discovery activity, searches for CNAB or certificate files, Pastebin configuration retrieval, and suspicious WebSocket traffic.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
In its BraZetsu analysis, Group-IB identified the Infect Marketplace vendor alias SpamPower as part of Exilware's restricted partner network, further connecting marketplace operations to the Brazilian actor.
Two compromised U.S. hosts were advertised through Infect Marketplace. Researchers said this could indicate possible geographic expansion, but did not establish a sustained shift from Exilware's Brazil, Iberia, and Latin America focus.
Group-IB tracked five BraZetsu versions from February through May 2026, documenting its evolution from a basic remote-access tool into an intelligence-gathering toolkit supporting initial-access brokering.
Exilware began operating the Infect Marketplace (also called Infected Marketplace/Banco de Infects) through infect[.]online, offering access to compromised hosts and allowing buyers to deploy secondary payloads.
Group-IB reported that BraZetsu collects host reconnaissance data and uses generative AI to assess the commercial value of compromised Windows systems before their access is offered through Infected Marketplace. This supports Exilware's apparent automation of access-broker inventory valuation and resale.
Group-IB reported that BraZetsu shares a CNAB-related directory list with CNABHunter, indicating that its developers may have incorporated similar CNAB-file discovery functionality. It also identified a BraZetsu loader masquerading as Microsoft Edge from caixaentradas1inboxshop[.]site, a domain previously used to distribute the Ousaban banking trojan.
Gurucul documented BraZetsu command-and-control and marketplace infrastructure, associated Pastebin payload/configuration URLs, and 16 SHA-256 indicators. The report also detailed reconnaissance of banking, ERP, e-commerce, industrial, and SCADA environments and theft of browser history, CNAB files, and digital certificates.
Group-IB assessed with high confidence that AgenteV2 and BraZetsu are the same initial-access malware framework, citing shared infrastructure, payload architecture, Python/Nuitka build artifacts, WebSocket backdoor features, Pastebin configuration retrieval, and related filenames.
Group-IB identified the Python-based Windows framework BraZetsu and attributed it to Brazilian threat actor Exilware with high confidence. It assessed BraZetsu as Exilware's primary tool for compromising and profiling systems to replenish Infect Marketplace inventory.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcexakep.ru
Open sourcethehackernews.com
Open sourcecommunity.gurucul.com
Open sourcecybersecuritynews.com
Open sourcegroup-ib.com
Open sourceany.run
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.