Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Access broker BraZetsu changed hosts nearly five months before the report that named it

Hunt.io found that BraZetsu's servers had moved hosts months before Group-IB's August 31 report named them. Defenders who block only the published addresses are pointing at infrastructure the operators had already abandoned.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Access broker BraZetsu changed hosts nearly five months before the report that named it
Generated illustration

What happened

  • BraZetsu breaks into Windows machines, scans them for ERP software, SCADA traces, EDR products and certificate files, then packages what it finds for sale.
  • Infected Marketplace, the group behind the tool, charges a deposit of about 5.80 Brazilian reais just to let buyers open its listings.
  • Group-IB's August 31 writeup named BraZetsu a Python framework compiled with Nuitka and tied it with high confidence to a Brazilian actor it calls Exilware.
  • The command hostname c2.installscenter.com had been serving TLS from a second server since April 4, sharing an IP with the panel hostname painel.installscenter.com at Swedish host Njalla.
  • Hunt.io notified the relevant national CERTs before publishing and says no victim data was recovered during its investigation.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Detection that outlasts a report keys on the hosting pattern Hunt.io flagged: a panel-prefix host on a non-standard port running Hestia Control Panel. That configuration held from February through June while the addresses rotated.
  • capability A buyer never needs to understand BraZetsu; they purchase a Windows host already broken into, so a ransomware crew skips the break-in and begins at deployment.
  • precedent Indicator feeds built from this kind of report decay within months; the malware alone cycled through five file hashes in four months.

Hunt.io did not take the binary apart again. "We didn't reverse the binary again. We took the published indicators and checked what our certificate inventory still shows," the firm said. [5] Binaries change all the time; a hostname tied to a valid TLS certificate is much harder to replace. [17] "An operator who keeps a panel and a command channel under the same apex, with Let's Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month," Hunt.io said. [6]

The trail begins on a Contabo server that ran the provider's default factory hostname from January into early February. [8] On February 11, around when Group-IB dates the first BraZetsu build, the certificate switched to painel.seu-dominio.com, a Portuguese placeholder meaning "your domain" lifted straight from hosting tutorials. [9] It appeared 17 times over five weeks, every two to four days, the sign of a panel kept running day to day. [9]

When the operators switched providers they changed nothing else. The new host came alive on March 21, the day the installscenter.com domain was registered. [10] Hunt.io's passive DNS shows c2.installscenter[.]com resolving to 80.78.27[.]252 between March 22 and 26, then to Cloudflare, while the only A record for painel.installscenter[.]com points to Cloudflare from March 21. [11] The TLS services on 80.78.27.252 went quiet after June 20. [12]

What to watch

  • Whether Njalla or Cloudflare act on the hostnames Hunt.io flagged, and whether the TLS trail reappears on a new provider.
  • Whether BraZetsu's operators rotate to a fresh apex or control-panel prefix now that the pattern is public.
  • Whether other trackers rebuild their BraZetsu detection around the hosting fingerprint rather than the published addresses.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Group-IB published a detailed writeup on BraZetsu on August 31, naming it a Python framework compiled with Nuitka and tying it with high confidence to a Brazilian actor called Exilware.

    ReportedSupportedView cited source
  2. [2]

    Hunt.io checked whether Group-IB's published indicators still held up against its own TLS certificate data and found the infrastructure had already moved on, quietly, months before anyone wrote about it.

    ReportedSupportedView cited source
  3. [3]

    BraZetsu is an initial access broker tool that breaks into Windows machines, checks them for ERP software, SCADA traces, EDR products and certificate files, then packages the information for sale.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. securityaffairs.com

    1 article · October 8, 2026

    Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories