A newly discovered malware framework dubbed BraZetsu is changing the cybercrime landscape, transforming compromised Windows machines into sellable assets on illicit marketplaces. The group behind it, known as Exilware, has developed a Python-based toolkit that goes beyond simple infostealers and catalogs infected hosts as commodities. The malware has been active since at least February 2026 and has already shown significant evolution in its capabilities and reach.
Modular Powerhouse Backed by AI
BraZetsu’s design consists of modular architecture and stealth techniques, allowing it to remain undetected by some antivirus tools, including undetected by VirusTotal in some cases. Its functions span from reconnaissance and system profiling to deep data extraction. It can access browser histories from major browsers (Chrome, Edge, Brave, Vivaldi, Opera), capture screen contents, gather environment variables, and search for financial remittance files in Brazil using the CNAB format. Generative AI plays a role in both data triage and prioritizing high-value compromised hosts. This complex toolset makes BraZetsu a high-end enabling technology for cybercriminal ecosystems.
The Infect Marketplace & Monetizing Access
At the heart of the operation is a marketplace called Infect Marketplace (also “Banco de Infects”, infect[.]online), where access to compromised hosts is sold—initially for about US$5.80. Once access is purchased, criminal customers can deploy their own payloads or tools directly through the platform without having to maintain the initial foothold themselves. As the tool has matured since early 2026, Exilware has been using BraZetsu to continuously feed this marketplace with new compromised systems, each profiled and priced based on their value.
Delivery Methods & Operational Scope
The malware appears to begin with a loader masquerading as Microsoft Edge, distributed via a domain named “caixaentradas1inboxshop[.]site”. Victims, particularly in Iberia and Latin America, receive phishing emails—often with PDF attachments—that lead them to malicious sites tailored to their locale. Execution typically involves Visual Basic Script (VBS) files that retrieve further payloads, including steganographic PNGs disguised as PDFs, which then unzip into dangerous DLLs executed via sideloading or process injection.
BraZetsu’s developers have been diversifying their approach. There are at least five distinct versions observed, with a gradual shift toward targeting primarily corporate infrastructure in Brazil. However, it remains multilingual and globally aware, with access to U.S. systems spotted on the marketplace. Correlations in code and infrastructure suggest BraZetsu is closely linked to a tool known as AgenteV2, which also uses Python, backdoors, real-time screen streaming, and phishing lures mimicking legal summons.
Why BraZetsu Is an Intelligence Multiplier
This framework isn’t just stealing data; it’s automating value assessment of victims through profiling hardware, software, and network setups. That enables Exilware to tailor access pricing—creating tiers of geographies, company types, and infrastructure readiness. The focus is increasingly laser-aimed at critical sectors in Latin America, especially Brazil, but with potential for expansion due to its multilingual support and flexible architecture.
As a tool for Initial Access Brokers (IABs), BraZetsu reflects a shift from classic malware paradigms toward platforms that treat systems like commodity inventory. Rather than each attacker having to build their own exploit pipeline, these marketplace models let actors plug into pre-built access, deploy tools, and reap rewards without reinventing initial compromise methods.
Security teams should keep a close eye on domain registrations mimicking trusted brands, phishing lures with financial themes, and anomalies in file formats used in payments. Defense strategies should include network segmentation, endpoint detection tuned for lateral movement and payload stagers, and rapid incident response protocols to contain infections early.