Security1 distinct publisher2 min readPublished
Group-IB says the Exilware crew built BraZetsu to score compromised Iberian and Latin American machines by value and sell entry to whoever wants to run their own payload, which changes how a stealer alert should be triaged.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Timing is what undercuts the standard response here. Group-IB's report describes a sequence with a sale in the middle of it: infect, enumerate, score, list, sell, then run the buyer's code [1][10]. Credential rotation only closes the first step in that chain, leaving the listing itself unaffected.
BraZetsu does the scoring before a broker sets a price. It performs deep reconnaissance and scans the network around the host, pulls browser history from Chrome, Edge, Brave, Vivaldi and Opera, takes screen captures, and collects digital certificates [19][11]. Group-IB attributes the back-end triage and target prioritisation to generative AI, which the analysts say the crew also used for development [6]. The product a buyer collects is therefore a pre-sorted entry point rather than an unlabelled shell, and the marketplace carries a feature to execute payloads remotely on purchased access without the buyer establishing a foothold at all [10]. Persistence to the platform runs over WebSocket [13].
Entry to the Infected Marketplace, also advertised as Banco de Infects and infect[.]online, takes an initial deposit of roughly $5.80 [7]. Exilware was first discovered on 2 February 2026 operating what Group-IB characterises as a basic remote access trojan; the modular Python framework was first seen in early May 2026 [8][9]. That is about three months from RAT to AI-assisted intelligence framework [17], and the marketplace is the thing the framework was rebuilt to feed.
The CNAB detail is where the two revenue models separate. BraZetsu hunts for corporate remittance files in the Brazilian Federation of Banks' fixed-width CNAB format, the standard used for payment interchange between companies and banks [12]. CNABHunter, which Group-IB says overlaps with BraZetsu, goes further: it parses those records, exfiltrates payment metadata, polls a server for operator orders, and on instruction rewrites the files to substitute attacker-controlled bank details, PIX keys or barcodes [14][15]. Group-IB places BraZetsu on the access side rather than the fraud side [16]. Read CNABHunter as the catalogue of what a buyer may do after purchase.
The evidence comes with two caveats worth flagging. This is one vendor's report, and the Portuguese-speaking attribution for Exilware is an assessment, not a claim of identity [4]. The observation that some samples were fully undetectable on VirusTotal is dated to the time of analysis, so it describes a snapshot of detection coverage rather than a permanent property of the samples [3].
For anyone inside the e-commerce, corporate, financial, industrial or law enforcement scope Group-IB names across Iberia and Latin America [5], a stealer ticket closed on password resets leaves the sellable part of the compromise intact. That is the argument for rebuilding the host and hunting laterally from it.
Ranked by verification strength, evidence, and original report placement.
Group-IB researchers disclosed BraZetsu, a Python-based Windows malware framework described as a master toolkit that empowers initial access brokers by turning compromised systems into commercial assets, rather than following the standard infostealer model.
Group-IB said the framework uses a modular architecture and stealth techniques that allowed some samples to remain fully undetectable on VirusTotal at the time of analysis.
The threat actors behind BraZetsu are tracked as Exilware and are believed to be native Portuguese speakers.
Group-IB said BraZetsu is primarily scoped to Iberian and Latin American targets in e-commerce, corporate, financial, industrial, law enforcement and other environments.
BraZetsu underpins the Infected Marketplace, also known as Banco de Infects and infect[.]online, where the actor monetises initial access to compromised hosts for an initial deposit of roughly $5.80.
The threat actor was first discovered on 2 February 2026 and rapidly evolved its toolset from a basic remote access trojan into the AI-enhanced intelligence-gathering framework.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Force the tool call, then hand Lightsail a long-lived key1 distinct publisher
build
A receipt intent written before dispatch turns an SMS timeout into a poll instead of a resend1 distinct publisher
build
TerminalFix delivers its first stage through the clipboard of the person it targets1 distinct publisher
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell6 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor report, relayed faithfully
The technical texture is real — named analysts, five named browsers, a fixed-width file format, a WebSocket channel, a live distribution domain, a plausible lineage story about copying CNABHunter's directory list a day after it was disclosed. But it all descends from a single Group-IB write-up carried by a single publisher, with no hashes, no sample count and, by the researchers' own admission, no established delivery chain. Specificity is not the same thing as corroboration.
A live storefront with no inventory count
There is genuine evidence of something operating: a framework seen in the wild since early May 2026, an actor tracked since February, samples that slipped past VirusTotal, a priced storefront with a payload-deployment feature, and a distribution domain with prior Ousaban traffic behind it. What is missing is any measure of size — no listings, no buyers, no victims, no revenue. A market that exists is not yet a market anyone has counted.
Vendor branding outruns the numbers
"Master toolkit," "threat-multiplier effect," a Naruto-derived codename and an AI angle are all doing rhetorical work the measurements do not yet support. The underlying mechanic — cheap resale of pre-scored footholds with buyer-supplied payloads — is well described and, if anything, its triage implications are understated relative to the marketing language wrapped around it.
Threat-intel naming rights
A commercial intelligence vendor gets paid in attention for christening a new actor and a new toolkit, and this report supplies both a name and a coinage with a manga reference attached. The relaying outlet has its own volume incentive around fresh malware names. None of that makes the findings wrong; it does explain why the framing is maximal and why the caveats sit at the bottom.
Plausible, unverified, single-channel
Everything in this story is internally consistent and matches known Brazilian cybercrime patterns, which is why it reads as credible — but consistency with expectations is a weak substitute for a second pair of eyes. Until another firm's telemetry, a sample set or law-enforcement action touches the same infrastructure, the confident parts are the mechanics and the uncertain parts are the scale, the AI claim and the delivery route.