Hackers Use AI Malware to Rank and Sell Access to Compromised Corporate Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Hackers are using a new Windows malware framework to turn corporate break-ins into products for sale. The tool, called BraZetsu, quietly maps a victim’s systems, finds valuable business data and helps criminals decide which footholds deserve the highest price.

The campaign is aimed mainly at organizations in Brazil and elsewhere in Iberia and Latin America.

It appears to arrive through social engineering, with files disguised as routine software or notices, before creating a channel that lets operators explore a compromised machine and deploy further payloads.

Analysts at Group-IB identified the malware and linked it with high confidence to a Brazilian actor tracked as Exilware.

Group-IB said in a report shared with Cyber Security News (CSN) that the operation developed from a basic remote-access tool into a framework built to support access brokers.

The threat goes beyond information theft. Criminals collect the details needed to package an infected company for buyers, creating a supply chain that can support fraud, data theft or ransomware. It reflects how access brokers fuel ransomware operations.

Hackers Use AI Malware

BraZetsu is written in Python and compiled into Windows executables, a choice that can make ordinary signature checks less effective.

Group-IB found that recent samples used a modular design, hid console activity and maintained an interactive WebSocket connection with command-and-control infrastructure.

Its standout feature is reconnaissance. The malware inventories the device, running programs, network ports and software linked to business functions.

Retrohunt matches common remittance paths (Source - Group-IB)
Retrohunt matches common remittance paths (Source – Group-IB)

It also searches browser history and financial remittance files, including Brazil’s CNAB format, while looking for digital certificates and signs of enterprise resource-planning, industrial-control, development, backup and security environments.

The code contains 27 functions, most focused on finding and describing valuable systems. It can capture screenshots and run commands remotely, giving an operator both automated results and the option of hands-on control.

This is the same broad risk behind AI built malware operations, where machine-assisted tooling can speed decisions after entry. Group-IB said verbose logs and emoji-heavy messages point to extensive use of generative AI during development.

More importantly, embedded strings indicate that a server-side AI component may process stolen information, judge whether a file is a priority and assess hardware and machine details. The researchers could not determine the full extent of AI use across the attack lifecycle.

This approach changes the economics of intrusion. Rather than manually checking every infected computer, the operation can label systems by their likely value and sell better-prepared access. It also helps explain why defenders should treat unusual discovery activity as seriously as an attempted data theft.

Marketplace Expands the Risk

Exilware has operated an underground service since February 2026, selling compromised hosts through its Infect Marketplace. Group-IB assesses that BraZetsu is the primary engine replenishing that inventory.

Buyers can acquire access and remotely launch their own secondary malware, separating the initial breach from the eventual attack.

The reported entry cost was about $5.80, which lowers the barrier for criminals to participate. The operators later restricted accounts, requiring customers to spend deposited funds within 24 hours on busy days or 49 hours on normal days.

Two United States hosts advertised in April suggest possible expansion beyond the operation’s usual regional focus, although that evidence alone does not prove a lasting change.

Comparison between CNABHunter and BraZetsu remittance paths (Source - Group-IB)
Comparison between CNABHunter and BraZetsu remittance paths (Source – Group-IB)

For defenders, that model means an infection may be only the opening stage. A company could first be profiled, then resold to a buyer with a different goal.

The pattern resembles brokered network access sales, which give ransomware crews and other actors a ready-made route into corporate environments.

Organizations should enable strong logging and monitoring on endpoints tied to finance and business-management systems, then segment critical assets to limit movement after a compromise.

Teams should investigate registry queries, software enumeration and searches for .cnab, .240, .400, .pfx and .p12 files, as well as suspicious WebSocket traffic to unfamiliar destinations.

They should also block or tightly control Pastebin and similar services when not needed, because BraZetsu uses them to retrieve encrypted configuration data.

Staff should verify unexpected software and notification files before opening them. Such caution remains important as phishing enabled remote access continues to give intruders a foothold.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxps://pastebin[.]com/raw/aF0WCxia Pastebin dead-drop resolver used to retrieve encrypted C2 configuration
URL hxxps://pastebin[.]com/raw/hM0nXNBP Pastebin dead-drop resolver used to retrieve encrypted C2 configuration
URL hxxps://pastebin[.]com/raw/9ChwVzzw Pastebin dead-drop resolver used to retrieve encrypted C2 configuration
Domain c2[.]installscenter[.]com BraZetsu command-and-control infrastructure
Domain infectonline[.]store Infrastructure associated with the operation
Domain infect[.]online Infect Marketplace domain
IP address 38[.]242[.]246[.]176 Previously observed infrastructure linked to the Infect Marketplace
File name wifi_driver.exe BraZetsu loader name observed in the campaign
File name pattern msedge[0-9].exe Loader naming pattern used to masquerade as Microsoft Edge
File name msedge04.exe Observed BraZetsu loader filename
File name agenteV2_historico_detect.dll AgenteV2 payload assessed as functionally equivalent to BraZetsu payload
File name temp_agente.dll BraZetsu payload identified by Group-IB
SHA-256 f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 BraZetsu-associated file hash
SHA-256 54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 BraZetsu-associated file hash
SHA-256 91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 BraZetsu-associated file hash
SHA-256 cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 BraZetsu-associated file hash
SHA-256 d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 BraZetsu-associated file hash
SHA-256 0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf BraZetsu-associated file hash
SHA-256 1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 BraZetsu-associated file hash
SHA-256 96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 BraZetsu-associated file hash
SHA-256 0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d BraZetsu-associated file hash
SHA-256 30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe BraZetsu-associated file hash
SHA-256 10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c BraZetsu-associated file hash
SHA-256 bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8 BraZetsu-associated file hash
SHA-256 93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88 BraZetsu-associated file hash
SHA-256 67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2 BraZetsu-associated file hash
SHA-256 c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138 BraZetsu-associated file hash
SHA-256 3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa BraZetsu-associated file hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Use AI Malware to Rank and Sell Access to Compromised Corporate Networks appeared first on Cyber Security News.