Hackers are using a new Windows malware framework to turn corporate break-ins into products for sale. The tool, called BraZetsu, quietly maps a victim’s systems, finds valuable business data and helps criminals decide which footholds deserve the highest price.
The campaign is aimed mainly at organizations in Brazil and elsewhere in Iberia and Latin America.
It appears to arrive through social engineering, with files disguised as routine software or notices, before creating a channel that lets operators explore a compromised machine and deploy further payloads.
Analysts at Group-IB identified the malware and linked it with high confidence to a Brazilian actor tracked as Exilware.
Group-IB said in a report shared with Cyber Security News (CSN) that the operation developed from a basic remote-access tool into a framework built to support access brokers.
The threat goes beyond information theft. Criminals collect the details needed to package an infected company for buyers, creating a supply chain that can support fraud, data theft or ransomware. It reflects how access brokers fuel ransomware operations.
Hackers Use AI Malware
BraZetsu is written in Python and compiled into Windows executables, a choice that can make ordinary signature checks less effective.
Group-IB found that recent samples used a modular design, hid console activity and maintained an interactive WebSocket connection with command-and-control infrastructure.
Its standout feature is reconnaissance. The malware inventories the device, running programs, network ports and software linked to business functions.

It also searches browser history and financial remittance files, including Brazil’s CNAB format, while looking for digital certificates and signs of enterprise resource-planning, industrial-control, development, backup and security environments.
The code contains 27 functions, most focused on finding and describing valuable systems. It can capture screenshots and run commands remotely, giving an operator both automated results and the option of hands-on control.
This is the same broad risk behind AI built malware operations, where machine-assisted tooling can speed decisions after entry. Group-IB said verbose logs and emoji-heavy messages point to extensive use of generative AI during development.
More importantly, embedded strings indicate that a server-side AI component may process stolen information, judge whether a file is a priority and assess hardware and machine details. The researchers could not determine the full extent of AI use across the attack lifecycle.
This approach changes the economics of intrusion. Rather than manually checking every infected computer, the operation can label systems by their likely value and sell better-prepared access. It also helps explain why defenders should treat unusual discovery activity as seriously as an attempted data theft.
Marketplace Expands the Risk
Exilware has operated an underground service since February 2026, selling compromised hosts through its Infect Marketplace. Group-IB assesses that BraZetsu is the primary engine replenishing that inventory.
Buyers can acquire access and remotely launch their own secondary malware, separating the initial breach from the eventual attack.
The reported entry cost was about $5.80, which lowers the barrier for criminals to participate. The operators later restricted accounts, requiring customers to spend deposited funds within 24 hours on busy days or 49 hours on normal days.
Two United States hosts advertised in April suggest possible expansion beyond the operation’s usual regional focus, although that evidence alone does not prove a lasting change.

For defenders, that model means an infection may be only the opening stage. A company could first be profiled, then resold to a buyer with a different goal.
The pattern resembles brokered network access sales, which give ransomware crews and other actors a ready-made route into corporate environments.
Organizations should enable strong logging and monitoring on endpoints tied to finance and business-management systems, then segment critical assets to limit movement after a compromise.
Teams should investigate registry queries, software enumeration and searches for .cnab, .240, .400, .pfx and .p12 files, as well as suspicious WebSocket traffic to unfamiliar destinations.
They should also block or tightly control Pastebin and similar services when not needed, because BraZetsu uses them to retrieve encrypted configuration data.
Staff should verify unexpected software and notification files before opening them. Such caution remains important as phishing enabled remote access continues to give intruders a foothold.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps://pastebin[.]com/raw/aF0WCxia |
Pastebin dead-drop resolver used to retrieve encrypted C2 configuration |
| URL | hxxps://pastebin[.]com/raw/hM0nXNBP |
Pastebin dead-drop resolver used to retrieve encrypted C2 configuration |
| URL | hxxps://pastebin[.]com/raw/9ChwVzzw |
Pastebin dead-drop resolver used to retrieve encrypted C2 configuration |
| Domain | c2[.]installscenter[.]com |
BraZetsu command-and-control infrastructure |
| Domain | infectonline[.]store |
Infrastructure associated with the operation |
| Domain | infect[.]online |
Infect Marketplace domain |
| IP address | 38[.]242[.]246[.]176 |
Previously observed infrastructure linked to the Infect Marketplace |
| File name | wifi_driver.exe |
BraZetsu loader name observed in the campaign |
| File name pattern | msedge[0-9].exe |
Loader naming pattern used to masquerade as Microsoft Edge |
| File name | msedge04.exe |
Observed BraZetsu loader filename |
| File name | agenteV2_historico_detect.dll |
AgenteV2 payload assessed as functionally equivalent to BraZetsu payload |
| File name | temp_agente.dll |
BraZetsu payload identified by Group-IB |
| SHA-256 | f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 |
BraZetsu-associated file hash |
| SHA-256 | 54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 |
BraZetsu-associated file hash |
| SHA-256 | 91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 |
BraZetsu-associated file hash |
| SHA-256 | cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 |
BraZetsu-associated file hash |
| SHA-256 | d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 |
BraZetsu-associated file hash |
| SHA-256 | 0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf |
BraZetsu-associated file hash |
| SHA-256 | 1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 |
BraZetsu-associated file hash |
| SHA-256 | 96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 |
BraZetsu-associated file hash |
| SHA-256 | 0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d |
BraZetsu-associated file hash |
| SHA-256 | 30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe |
BraZetsu-associated file hash |
| SHA-256 | 10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c |
BraZetsu-associated file hash |
| SHA-256 | bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8 |
BraZetsu-associated file hash |
| SHA-256 | 93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88 |
BraZetsu-associated file hash |
| SHA-256 | 67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2 |
BraZetsu-associated file hash |
| SHA-256 | c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138 |
BraZetsu-associated file hash |
| SHA-256 | 3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa |
BraZetsu-associated file hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Hackers Use AI Malware to Rank and Sell Access to Compromised Corporate Networks appeared first on Cyber Security News.
