BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
AI Summary
BraZetsu is a sophisticated Python-based Windows malware framework used by the threat actor Exilware to compromise systems and monetize access via the 'Infected Marketplace' (aka 'Banco de Infects'). The malware conducts deep reconnaissance, steals financial data including CNAB-format remittance files, captures screenshots, and enables remote command execution. It leverages generative AI for target triage and prioritization, and maintains persistent communication via WebSocket. BraZetsu shares infrastructure and code with AgenteV2, indicating they are part of the same malware framework. The campaign primarily targets Iberian and Latin American organizations in e-commerce, finance, and critical infrastructure sectors.
AI-extracted · verify before operational use