Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ยท confidence: reported ยท severity: medium ยท affected_sectors: ยท au_impact: false

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Incident note โ€” 3 September 2026

On 3 September 2026, Group-IB disclosed BraZetsu, a Python-based Windows malware framework attributed with high confidence to the Brazilian threat actor known as Exilware. It functions as the primary technical mechanism for an Initial Access Broker (IAB) operation that commercialises footholds through an underground marketplace referred to as the 'Infect Marketplace'.

The operation feeds compromised hosts โ€” primarily in Iberian and Latin American environments โ€” into a catalogue that buyers can purchase for subsequent intrusion activity. Group-IB highlights the AI-enhanced framing of the campaign, as well as BraZetsu's modular structure and stealth characteristics, which left some samples undetectable on VirusTotal at the time of analysis.

The direct impact on Australian entities is assessed as low, though the broader supply-chain and credential-resale risk warrants attention given the reach into Spanish- and Portuguese-language regions where Australian businesses may operate.