Security1 publisherNot yet confirmed elsewhere2 min readPublished
Access broker BraZetsu changed hosts nearly five months before the report that named it
Hunt.io found that BraZetsu's servers had moved hosts months before Group-IB's August 31 report named them. Defenders who block only the published addresses are pointing at infrastructure the operators had already abandoned.
The Watch · Security desk

What happened
- BraZetsu breaks into Windows machines, scans them for ERP software, SCADA traces, EDR products and certificate files, then packages what it finds for sale.
- Infected Marketplace, the group behind the tool, charges a deposit of about 5.80 Brazilian reais just to let buyers open its listings.
- Group-IB's August 31 writeup named BraZetsu a Python framework compiled with Nuitka and tied it with high confidence to a Brazilian actor it calls Exilware.
- The command hostname c2.installscenter.com had been serving TLS from a second server since April 4, sharing an IP with the panel hostname painel.installscenter.com at Swedish host Njalla.
- Hunt.io notified the relevant national CERTs before publishing and says no victim data was recovered during its investigation.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Detection that outlasts a report keys on the hosting pattern Hunt.io flagged: a panel-prefix host on a non-standard port running Hestia Control Panel. That configuration held from February through June while the addresses rotated.
- capability A buyer never needs to understand BraZetsu; they purchase a Windows host already broken into, so a ransomware crew skips the break-in and begins at deployment.
- precedent Indicator feeds built from this kind of report decay within months; the malware alone cycled through five file hashes in four months.
Hunt.io did not take the binary apart again. "We didn't reverse the binary again. We took the published indicators and checked what our certificate inventory still shows," the firm said. [5] Binaries change all the time; a hostname tied to a valid TLS certificate is much harder to replace. [17] "An operator who keeps a panel and a command channel under the same apex, with Let's Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month," Hunt.io said. [6]
The trail begins on a Contabo server that ran the provider's default factory hostname from January into early February. [8] On February 11, around when Group-IB dates the first BraZetsu build, the certificate switched to painel.seu-dominio.com, a Portuguese placeholder meaning "your domain" lifted straight from hosting tutorials. [9] It appeared 17 times over five weeks, every two to four days, the sign of a panel kept running day to day. [9]
When the operators switched providers they changed nothing else. The new host came alive on March 21, the day the installscenter.com domain was registered. [10] Hunt.io's passive DNS shows c2.installscenter[.]com resolving to 80.78.27[.]252 between March 22 and 26, then to Cloudflare, while the only A record for painel.installscenter[.]com points to Cloudflare from March 21. [11] The TLS services on 80.78.27.252 went quiet after June 20. [12]
What to watch
- Whether Njalla or Cloudflare act on the hostnames Hunt.io flagged, and whether the TLS trail reappears on a new provider.
- Whether BraZetsu's operators rotate to a fresh apex or control-panel prefix now that the pattern is public.
- Whether other trackers rebuild their BraZetsu detection around the hosting fingerprint rather than the published addresses.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Group-IB published a detailed writeup on BraZetsu on August 31, naming it a Python framework compiled with Nuitka and tying it with high confidence to a Brazilian actor called Exilware.
- [2]
Hunt.io checked whether Group-IB's published indicators still held up against its own TLS certificate data and found the infrastructure had already moved on, quietly, months before anyone wrote about it.
- [3]
BraZetsu is an initial access broker tool that breaks into Windows machines, checks them for ERP software, SCADA traces, EDR products and certificate files, then packages the information for sale.
- [4]
The group behind BraZetsu, called Infected Marketplace, charges a deposit of about 5.80 Brazilian reais to let buyers browse the listings.
- [5]
"We didn't reverse the binary again. We took the published indicators and checked what our certificate inventory still shows."
- [6]
"The premise is narrow. An operator who keeps a panel and a command channel under the same apex, with Let's Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month."
- [7]
The command server hostname c2.installscenter.com had been using TLS on a second server since April 4, almost five months before the August report, on the same IP address as the control panel hostname painel.installscenter.com; both were hosted by the Swedish provider Njalla.
- [8]
The original seed IP, a Contabo server, served Contabo's default factory hostname from January through early February.
- [9]
On February 11, around when Group-IB dates the first BraZetsu version, the certificate switched to painel.seu-dominio.com, a Portuguese placeholder meaning "your domain" lifted from hosting tutorials; it showed up 17 separate times over five weeks, every two to four days.
- [10]
When the operators moved providers they kept the same habits: the new host came alive on March 21, the day the installscenter.com domain was registered, running the identical Hestia Control Panel setup with the same painel prefix.
- [11]
Hunt.io's passive DNS shows c2.installscenter.com resolving to 80.78.27.252 between March 22 and 26 and to Cloudflare (104.21.78.246, 172.67.138.224) from March 26 on; the only A record it has for painel.installscenter.com is Cloudflare, from March 21.
- [13]
The malware's hashes rotated across five different versions in just four months, useless as a long-term detection signal.
- [14]
What held steady from February through June was the naming convention and hosting pattern itself: a panel prefix on a nonstandard port, running on a VPS configured with Hestia Control Panel.
- [15]
Before publishing, Hunt.io notified the relevant national CERTs and confirmed no victim data was recovered during the investigation.
- [16]
The buyer who later deploys ransomware or steals money from a bank account doesn't need to know how BraZetsu works; they simply buy a machine that has already been compromised.
- [17]
Binaries can change all the time, but a hostname linked to a valid TLS certificate is much harder to replace.
Sources
1 independent publisher whose own reporting we read for this story.
- securityaffairs.comHunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Threat Infrastructure TrackingFollow
- Indicators of compromise and detection durabilityFollow
- Initial Access BrokersFollow