Hunt.io identified additional infrastructure associated with BraZetsu, a Windows malware framework used to compromise machines and inventory access for resale through Infected Marketplace. Group-IB previously attributed the Python-based framework, compiled with Nuitka, to Brazilian actor Exilware with high confidence. Certificate records showed the disclosed command-and-control hostname, c2.installscenter.com, serving TLS on 80.78.27[.]252 from April 4, 2026, alongside painel.installscenter.com—almost five months before Group-IB’s August 31 disclosure. Retained Portuguese panel naming and Hestia Control Panel configurations supported a medium-confidence assessment that the operation migrated from a Contabo VPS to a Njalla VPS.
The host’s relevant TLS services disappeared in June, and subsequent service and SSH-key changes mean defenders should not treat the IP as currently malicious without validation. Wildcard certificates issued as recently as October 2 indicate continued domain-zone activity but do not prove the command-and-control service remains operational. Hunt.io recommended hunting for recurring hostname, certificate, and endpoint patterns rather than relying solely on rapidly changing IP addresses or malware hashes, and notified relevant national CERTs before publication.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
Certificate Transparency logs recorded a wildcard certificate for *.installscenter.com issued on October 2, 2026. Researchers said continuing issuance suggested an active domain zone but did not establish that the command-and-control service remained operational.
On August 31, 2026, Group-IB disclosed BraZetsu as a Windows Python framework compiled with Nuitka and attributed it with high confidence to the Brazilian actor Exilware. The report linked the malware's host-inventory capabilities to access sales through Infected Marketplace.
A different SSH-key set appeared on 80.78.27.252 from July 24, 2026; the host subsequently served an nginx Laravel login without installscenter.com certificates. These changes led researchers to caution against treating the IP as currently malicious without validating its present use.
The relevant TLS ports on 80.78.27.252 went quiet between June 16 and June 20, 2026. Hunt.io placed the end of the assessed operator window on June 20.
On May 16, 2026, painel.installscenter.com was first observed on port 8083 at the replacement host. The retained Hestia setup and painel naming convention contributed to Hunt.io's medium-confidence continuity assessment.
On April 6, 2026, painel.installscenter.com was first observed on port 8443 at 80.78.27.252. Its presence alongside the command hostname expanded the infrastructure links beyond the originally published indicators.
On April 4, 2026, Hunt.io first observed c2.installscenter.com serving TLS on port 2083 at 80.78.27.252. This established that the replacement command infrastructure was observable almost five months before Group-IB's public disclosure.
From March 26, 2026, Hunt.io observed c2.installscenter.com resolving to Cloudflare addresses 104.21.78.246 and 172.67.138.224 rather than directly to the Njalla host. Researchers did not observe agent traffic and could not confirm the proposed proxy-routing arrangement.
Certificate Transparency recorded issuance for c2.installscenter.com on March 22, 2026. Passive DNS showed the hostname resolving directly to 80.78.27.252 between March 22 and March 26.
On March 21, 2026, the replacement host at 80.78.27.252 appeared and installscenter.com was registered through Tucows. Certificate Transparency recorded issuance for painel.installscenter.com that day, while its recorded DNS history began with Cloudflare addresses.
The seed host went quiet on March 20, 2026, immediately before replacement infrastructure appeared. Hunt.io later assessed continuity between the two hosts with medium confidence, without a shared certificate proving migration.
On February 11, 2026, 38.242.246.176 began presenting a self-signed certificate for painel.seu-dominio.com on port 8083 and briefly on port 443. Seventeen observations through March 17 supported sustained panel operation rather than a short-lived landing page.
Between February and May 2026, BraZetsu evolved through five generations, progressing from a remote-access tool with MonitorSystem Run-key persistence to a platform with 27 functions, mostly for enumeration. It profiled compromised Windows machines to support access sales through Infected Marketplace.
The subsequently identified BraZetsu seed IP, 38.242.246.176, presented the default certificate name vmi3003111.contaboserver.net in 80 observations between January 4 and February 2, 2026.
Hunt.io's certificate-inventory investigation added 80.78.27.252, panel certificate names, and ports 8083 and 2083 to the known infrastructure picture, while assessing migration from Contabo to Njalla with medium confidence. The researchers recommended tracking recurring hostname, certificate, and endpoint patterns rather than relying solely on changing IP addresses or malware hashes.
Hunt.io notified relevant national CERTs about the newly identified infrastructure before publishing its findings. Researchers recovered no victim data during the investigation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.