BraZetsu Malware Turns Compromised Windows PCs Into Paid Access for Cybercriminals
Cybersecurity researchers have uncovered a sophisticated Python-based Windows malware framework called BraZetsu that is being used to help Initial Access Brokers (IABs) compromise systems and sell access to other cybercriminals.
Researchers from Group-IB said BraZetsu is more than a conventional information-stealing malware. The framework is designed to identify valuable compromised systems, collect intelligence about victims and feed that information into an underground marketplace where other criminals can purchase access.
BraZetsu Malware Linked to Exilware
BraZetsu is operated by a threat actor tracked as Exilware, which researchers believe is associated with Portuguese-speaking operators.
The malware primarily targets organizations and users across Iberia and Latin America, including sectors such as:
- E-commerce
- Finance
- Manufacturing
- Corporate organizations
- Law enforcement
- Industrial environments
Group-IB researchers said BraZetsu demonstrates a high level of operational maturity, using a modular architecture and stealth techniques. Some samples were reportedly undetected by VirusTotal at the time of analysis.
The name BraZetsu combines "Brazil" with "Zetsu," a fictional character from the Japanese manga series Naruto known for operating from the shadows.
Malware Powers an Underground Access Marketplace
BraZetsu serves as the foundation for an underground platform called the Infected Marketplace, also known as "Banco de Infects" and associated with the domain infect[.]online.
The marketplace allows criminals to purchase access to compromised computers for an initial deposit of approximately $5.80.
After purchasing access, customers can remotely deploy their own malware or other malicious tools onto the compromised system through the marketplace.
This effectively creates an Access-as-a-Service model.
Instead of every criminal having to develop their own phishing campaign, malware loader or initial-access operation, they can simply purchase an already-compromised machine and use it for their own attacks.
AI Used to Identify Valuable Victims
One of the most notable aspects of BraZetsu is its use of generative AI.
According to Group-IB, AI is being used not only during malware development but also for data triage and victim prioritization.
The malware can evaluate compromised systems based on hardware, installed software and network infrastructure. This information helps operators determine which machines have greater commercial value.
The framework can therefore help Exilware automatically categorize compromised systems and determine which access is potentially more valuable to other cybercriminals.
BraZetsu Capabilities
The modular malware framework is capable of extensive reconnaissance and information collection.
Researchers identified capabilities including:
- Scanning infected hosts and networks
- Collecting digital certificates
- Extracting browser history
- Monitoring user activity through screenshots
- Collecting financial files
- Searching for Brazilian CNAB financial transaction files
- Executing commands through a remote shell
- Collecting information about running processes
- Enumerating network ports and environment variables
- Identifying active application windows
- Searching for recently opened files
- Locating ERP installation directories
- Deploying additional malware modules
- Maintaining persistent communication with its infrastructure
BraZetsu specifically searches for CNAB files, a Brazilian financial file format used for electronic transaction processing between companies and banks.
Connection to Financial Fraud Malware
Researchers also identified similarities between BraZetsu and another Python-based tool known as CNABHunter.
CNABHunter searches local and network directories for CNAB files, parses financial transaction information and sends payment-related metadata to attacker-controlled infrastructure.
It can also modify legitimate payment information inside CNAB files, replacing it with attacker-controlled banking details, PIX keys or barcodes.
However, Group-IB believes BraZetsu is primarily focused on initial access and intelligence gathering, rather than directly conducting financial fraud.
The two tools share a directory list used to locate CNAB files, suggesting that BraZetsu's developers may have adopted the functionality after recognizing its potential value.
How BraZetsu Reaches Victims
The exact initial delivery mechanism remains unclear, but researchers believe social engineering and phishing are likely involved.
One observed loader masquerades as Microsoft Edge and is distributed through a malicious domain.
Researchers discovered Visual Basic Script files associated with the infrastructure that download additional stages of the malware.
The same infrastructure has also been associated with the Ousaban banking trojan, suggesting possible overlap in delivery infrastructure or targeting.
Multiple Versions Detected
Researchers have identified five versions of BraZetsu in the wild.
The earliest known version dates back to February 9, 2026.
Later versions evolved significantly, with one generation becoming more focused on corporate targets in Brazil.
Despite the primary focus on Brazilian infrastructure in recent versions, researchers have also observed evidence of access being advertised for compromised systems located in the United States.
Link to AgenteV2
Group-IB also identified infrastructure and code similarities connecting BraZetsu to another Python-based backdoor known as AgenteV2.
One IP address associated with BraZetsu had previously been linked to AgenteV2 campaigns targeting Brazilian users through phishing messages designed to impersonate judicial summons.
AgenteV2 can stream a victim's screen to attackers in real time, allowing criminals to monitor activity when a banking website is opened.
Based on similarities in the codebase, infrastructure, techniques and functionality, Group-IB assessed with high confidence that AgenteV2 and BraZetsu represent the same initial-access malware framework.
BraZetsu Creates a Cybercrime Force Multiplier
The biggest concern surrounding BraZetsu is not simply its ability to steal information.
Its integration with an underground marketplace allows one compromised machine to become an entry point for multiple criminal operations.
An Initial Access Broker can compromise a system, collect intelligence about it and sell access. A second criminal can then purchase that access and deploy additional malware without having to compromise the victim independently.
This creates a cybercrime supply chain in which initial access can be repeatedly monetized.
Threat Extends Across Latin America
BraZetsu is part of a broader trend involving malware campaigns targeting organizations across Latin America.
Researchers have also reported activity from other threat actors targeting Brazil, Chile, Colombia, Ecuador and Venezuela.
The region has increasingly become a target for financially motivated cybercrime and cyber-espionage operations, particularly against financial institutions, government organizations and businesses.
Key Takeaways
- BraZetsu is a Python-based Windows malware framework.
- It is linked to the threat actor Exilware.
- The malware supports an underground Access-as-a-Service marketplace.
- Compromised systems can reportedly be purchased for an initial deposit of around $5.80.
- BraZetsu uses AI-assisted analysis to identify potentially valuable victims.
- It searches for sensitive financial information, including Brazilian CNAB files.
- Researchers identified five versions of the malware.
- BraZetsu shares significant similarities with AgenteV2.
- The framework primarily targets organizations across Brazil, Iberia and Latin America.
- The marketplace allows other criminals to deploy additional malware after purchasing access.
SEO Keywords: BraZetsu malware, BraZetsu malware 2026, Exilware cybercrime, Windows malware, Initial Access Broker, IAB marketplace, Infected Marketplace, Brazil cybersecurity, Latin America cyber attacks, Python malware, AI-powered malware, CNAB malware, AgenteV2, cybersecurity news