Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem

    Date: 09/02/2026

    Severity: Medium

    Summary

    BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, designed to support Initial Access Broker (IAB) operations. It performs deep reconnaissance of banking, ERP, e-commerce, industrial/SCADA systems, and steals browser history, CNAB financial files, and digital certificates for monetization through the Infected Marketplace (Banco de Infects). Its modular architecture, stealth capabilities, and extensive use of generative AI for development and potentially data triage highlight an evolving threat to Iberian and Latin American organizations.  

    Indicators of Compromise (IOC) List 

    Domains/URLs

    https://pastebin.com/raw/aF0WCxia

    https://pastebin.com/raw/hM0nXNBP

    https://pastebin.com/raw/9ChwVzzw

    c2.installscenter.com

    infectonline.store

    infect.online

    IP Address

    38.242.246.176

    Hash

    f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17

    54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700

    91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0

    cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78

    d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99

    0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf

    1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246

    96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042

    0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d

    30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe

    10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c

    bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8

    93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88

    67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2

    c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138

    3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://pastebin.com/raw/9ChwVzzw" or url like "https://pastebin.com/raw/9ChwVzzw" or siteurl like "https://pastebin.com/raw/9ChwVzzw" or domainname like "https://pastebin.com/raw/aF0WCxia" or url like "https://pastebin.com/raw/aF0WCxia" or siteurl like "https://pastebin.com/raw/aF0WCxia" or domainname like "c2.installscenter.com" or url like "c2.installscenter.com" or siteurl like "c2.installscenter.com" or domainname like "infect.online" or url like "infect.online" or siteurl like "infect.online" or domainname like "https://pastebin.com/raw/hM0nXNBP" or url like "https://pastebin.com/raw/hM0nXNBP" or siteurl like "https://pastebin.com/raw/hM0nXNBP" or domainname like "infectonline.store" or url like "infectonline.store" or siteurl like "infectonline.store"

    Detection Query 2 :

    dstipaddress IN ("38.242.246.176") or srcipaddress IN ("38.242.246.176")

    Detection Query 3 :

    sha256hash IN ("91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0","54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700","c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138","0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d","d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99","bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8","96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042","67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2","f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17","1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246","10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c","3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa","30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe","cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78","93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88","0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf")

    Reference:    

    https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/                                          


    Tags

    MalwareThreat ActorPythonBrazilCommercial FacilitiesFinancial ServicesData StealerAILatin America

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags