Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Tesla is asking people if they want to buy and run Cybercab fleets

    September 4, 2026

    Google DeepMind’s WeatherNext 3 Trains on Weather Station Observations to Deliver 5 km Global Forecasts, Refreshed Every Hour

    September 4, 2026

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    September 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Tesla is asking people if they want to buy and run Cybercab fleets
    • Google DeepMind’s WeatherNext 3 Trains on Weather Station Observations to Deliver 5 km Global Forecasts, Refreshed Every Hour
    • BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
    • Tether Sued Over Frozen ‘Pig Butcher’ Coins, 6,600 Students Get Crypto Loans: Asia Express
    • Cherokee youth win legal rights for waterway in first all-female U.S. effort
    • US billionaire Leon Black defies summons and sues Epstein panel
    • Minister tells Brits to stock up on days of supplies after ‘supersize’ El Niño warning | El Niño southern oscillation
    • Wikipedia Workers Unionize for the First Time
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 4, 2026 Cybersecurity No Comments8 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.

    “Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets,” Group-IB malware analysts Julio Guapo Menezes and Miguel Salazar said in a technical report.

    “The framework exhibits high operational maturity, utilizing a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis.”

    BraZetsu is a portmanteau of “Brazil” and “Zetsu,” a fictional character from the Japanese Manga series Naruto who is known to operate as a threat from the shadows. The naming is inspired by the fact that the initial access tool stealthily infiltrates target networks to conduct highly destructive follow-on attacks. The threat actors, tracked as Exilware, are believed to be native Portuguese speakers.

    The Singapore-headquartered company said BraZetsu is primarily scoped to target Iberian and Latin American targets in e-commerce, corporate, financial, industrial, law enforcement, and other environments. Evidence points to heavy use of generative artificial intelligence (AI) for not just malware development, but also backend data triage and target prioritization.

    The malware harbors capabilities to conduct deep reconnaissance and scan victim networks. For financial remittance files, such as those in the Brazilian CNAB format, a fixed-width text file standard used for electronic data interchange (EDI) of financial transactions between companies and banks in Brazil. It’s also equipped to extract detailed browser histories to get an understanding of victim activity.

    Cybersecurity

    BraZetsu forms the foundation for the Infected Marketplace (aka “Banco de Infects”, “infect[.]online”), a platform where the threat actor monetizes initial access to compromised hosts for an initial deposit of roughly $5.80. The threat actor was first discovered on February 2, 2026, rapidly evolving its toolset from a basic remote access trojan to the AI-enhanced intelligence-gathering framework it is today.

    “By functioning as a service-enabled platform, the marketplace allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect across the regional ecosystem,” the researchers said.

    “The marketplace functions as an access-as-a-service operation, in which other criminals can purchase entry points into victims’ systems. Once a criminal purchases access through the marketplace, they can deploy malicious payloads via a specialized platform feature. This allows buyers to remotely execute their own malware or tools on the compromised systems without needing to establish the initial foothold themselves.”

    The modular Python framework, per Group-IB, was first seen in early May 2026, and offers a way for the operators to catalog compromised systems as “tradable assets” for secondary threat actors on the marketplace. It supports the following functions –

    • Scans infected hosts and uses generative AI to triage data and prioritize high-value targets for IABs
    • Collects digital certificates, browser histories from Google Chrome, Microsoft Edge, Brave, Vivaldi, and Opera, and financial files while tracking user behavior through screen captures
    • Attempts to locate corporate financial remittance files in the Brazilian Federation of Banks’ CNAB format
    • Relies on the WebSocket protocol to maintain persistent communication with the Infected Marketplace

    BraZetsu also shares some level of overlap with CNABHunter, a custom Python tool that systemically scans local and network directories for CNAB files, parses financial transaction records, and exfiltrates payment metadata to a dedicated HTTP-based infrastructure. Furthermore, CNABHunter polls a remote server for operator-issued orders.

    “When instructed, it automatically rewrites the original CNAB files by replacing legitimate payment information with attacker-controlled banking details, PIX keys, or barcodes,” Group-IB said. “This workflow is specifically designed to facilitate financial fraud against corporate payment processes.”

    On the other hand, BraZetsu is more geared towards initial access rather than an implement for financial fraud. Besides performing broad host reconnaissance and gathering CNAB-related files, it facilitates autonomous data collection, interactive, hands-on operations through remote shell command execution, and the deployment of additional worker modules.

    The core aspect that ties them together is the directory list used to locate CNAB-related files. It’s suspected that the developers associated with BraZetsu incorporated the same functionality after seeing a “profitable opportunity.” This assessment is based on the fact that BraZetsu was discovered in the wild a day after CNABHunter was publicly disclosed by a researcher named @johnk3r on X.

    Exactly how this malware is delivered to victims remains unclear at this stage. However, social engineering is the most likely culprit. The starting point is a loader that masquerades as Microsoft Edge and is downloaded from a distribution domain named “caixaentradas1inboxshop[.]site.”

    An analysis of the files associated with the domain has uncovered Visual Basic Script (VBS) files responsible for downloading the next stage of the attack. Interestingly, the same domain has been used to deliver the Ousaban banking trojan. In May 2026, Fortinet FortiGuard Labs said it identified an email phishing attack targeting users in the Iberian Peninsula with an MSI downloader that deploys Ousaban.

    “The phishing PDF tricks victims into visiting a malicious webpage that scans the user’s environment,” Fortinet said in a report published in July. “If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack. The final payload is an EXE file that is dropped onto the victim’s computer and executed by the VBS script.”

    The VBS file is designed to retrieve a steganographic PNG image that mimics a PDF document, which then extracts a ZIP file from the image and extracts from it the Ousaban DLL. The final payload is then run via DLL sideloading or process injection.

    Like in the case of Ousaban, BraZetsu uses a Pastebin URL to extract the C2 information. It also incorporates dedicated functions to obtain the user’s active application window title and, if it contains common banking keywords; enumerate environment variables, network ports, and running processes; run shell commands; capture screenshots; fetch recently opened files; and locate common Enterprise Resource Planning (ERP) installation directories.

    In all, five distinct versions of the malware have been detected in the wild to date, with the earliest iteration dating back to February 9, 2026. The third generation is notable for narrowing its operational focus to corporate targets in Brazil. That said, the threat actor has been observed advertising access to two compromised hosts located in the U.S. around the same time.

    Cybersecurity

    “BraZetsu functions as the primary malware framework supporting Exilware’s Initial Access Broker (IAB) operation by establishing initial footholds and continuously replenishing the Infect Marketplace inventory,” Group-IB said.

    A deeper hunt for artifacts matching the naming convention used by Exilware has also identified an IP address (“38.242.246[.]176”) that has been previously tied to AgenteV2, a Python-based backdoor that has targeted Brazilian users via phishing lures impersonating judicial summons. The malware is engineered to stream a victim’s screen to the attacker in real-time to facilitate financial fraud as soon as a banking portal is launched.

    Based on shared codebase, tradecraft, infrastructure, and functional capabilities, Group-IB has assessed with high confidence that both AgenteV2 and BraZetsu refer to the same initial access malware framework.

    “The malware’s AI-driven assessment capabilities automatically evaluate compromised machines’ commercial potential through hardware profiling, software environment analysis, and network infrastructure mapping, enabling Exilware to categorize automatically and price marketplace access based on victim value,” the company said.

    “Recent versions show an exclusive focus on Brazilian infrastructure while maintaining multi-language capabilities for regional expansion, indicating deep operational knowledge of the domestic threat landscape and strategic positioning for broader Latin American operations targeting critical infrastructure and high-value commercial sectors.”

    BraZetsu is far from the only malware that has targeted Latin America. In recent weeks, Dark Caracal, a cyber espionage group with ties to Lebanon’s General Directorate of General Security, has been attributed to a targeted intrusion affecting a communications organization in Venezuela.

    The incident, which took place in June 2026, resulted in the deployment of a previously undocumented Go-based modular framework codenamed GoCaracal and an updated version of Bandook. GoCaracal appears in two variants: a lightweight implant that establishes initial access and drops additional payloads, and an extended build for sustained intelligence collection and interactive control.

    “The extended build also supports an Ethereum smart-contract fallback that allows operators to retrieve replacement command-and-control (C2) infrastructure without redeploying the malware,” ArcticWolf said. “These findings show that Dark Caracal is modernizing the malware and infrastructure behind its established operations and tradecraft.”

    The delivery method is consistent with a previous campaign documented by Kaspersky in which the threat actor used invoice-themed lures containing SVG attachments to distribute a backdoor called AsioGate, a successor to Poco RAT, via a Delphi loader in attacks targeting users and entities in Chile and Brazil.

    The findings also come as LevelBlue found that an operator linked to Blind Eagle had their own machine compromised by an information stealer, offering crucial insights into the campaign. Blind Eagle is a Spanish-speaking hacking group active since at least 2018, primarily targeting government agencies, financial institutions, and corporate entities in Latin America, particularly in Colombia and Ecuador.

    “What we found on that machine provided a much broader picture of the operation: RAT-building tools, phishing templates, bulk-email software, infrastructure records, and evidence of repeated efforts to make malicious files harder for security software to detect,” security researcher Serhii Melnyk said.

    “The machine appears to have been compromised by an unrelated commodity infostealer – the same general type of malware that Blind Eagle uses to steal information from victims. In other words, the trail began when an apparent attacker-side workstation was itself exposed by someone else’s malware.”

    BraZetsu Compromised criminal hosts inventory Malware Marketplace turns Windows
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Elementor Pro flaw exploited to take over WordPress sites

    French hospital fined €500,000 after breach exposes data of 727,000

    Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

    Coder’s registry infrastructure compromised to push malicious modules

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Tesla is asking people if they want to buy and run Cybercab fleets

    September 4, 2026

    Google DeepMind’s WeatherNext 3 Trains on Weather Station Observations to Deliver 5 km Global Forecasts, Refreshed Every Hour

    September 4, 2026

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    September 4, 2026

    Tether Sued Over Frozen ‘Pig Butcher’ Coins, 6,600 Students Get Crypto Loans: Asia Express

    September 4, 2026
    Latest Posts

    Ultrafast X-rays capture chemistry unfolding atom by atom

    July 31, 2026

    How a PPE company’s highly publicized $32M Bitcoin strategy quietly expired without purchasing a single coin

    July 31, 2026

    Critical Flaw Led to Azure Cosmos DB Pwnage

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Tesla is asking people if they want to buy and run Cybercab fleets

    September 4, 2026

    Google DeepMind’s WeatherNext 3 Trains on Weather Station Observations to Deliver 5 km Global Forecasts, Refreshed Every Hour

    September 4, 2026

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.