A Python-based Windows malware framework called BraZetsu is quietly stockpiling compromised hosts and feeding them to an underground marketplace where criminals can buy their way into victim networks, according to researchers at Group-IB.
The Singapore-headquartered firm says the modular toolkit, which it attributes to a Portuguese-speaking actor it tracks as Exilware, acts as the engine for the Infected Marketplace, also known as Banco de Infects. Access to compromised machines sells from a deposit of roughly $5.80, and buyers can then remotely execute their own payloads on purchased hosts without ever establishing a foothold themselves. Group-IB calls the setup an access-as-a-service operation that turns infected systems into tradable assets.
BraZetsu’s targets skew toward e-commerce, corporate, financial, industrial, and law enforcement environments in Iberia and Latin America, with recent versions narrowing focus to Brazilian infrastructure. The malware scrapes browser histories from Chrome, Edge, Brave, Vivaldi, and Opera, collects digital certificates, hunts for Brazilian CNAB bank remittance files, and captures screenshots to map victim activity. Group-IB says the operators lean on generative AI for development, data triage, and target prioritization, letting the framework price access based on each machine’s commercial potential.
Five versions have been spotted since February 9, 2026, and some samples stayed fully undetectable on VirusTotal at analysis time. Communication with the marketplace runs over WebSocket, and the tool shares code, infrastructure, and tradecraft with AgenteV2, a Python backdoor tied to phishing lures impersonating Brazilian judicial summons, which Group-IB now assesses to be the same framework.
The company advises defenders to watch for masquerading Microsoft Edge loaders, steganographic PNG delivery, and unexpected outbound WebSocket traffic to known marketplace infrastructure.
