BraZetsu est un framework malveillant Python, compilé avec Nuitka, attribué à Exilware. Group-IB établit avec haute confiance que BraZetsu et AgenteV2 sont le même framework.
BraZetsu
BraZetsu is a Python-based Windows backdoor and initial-access-broker framework attributed with high confidence to the Brazilian cybercriminal actor Exilware.
Profile source: Mallory opens in a new tabBraZetsu
Family profile
BraZetsu is a Python-based Windows backdoor and initial-access-broker framework attributed with high confidence to the Brazilian cybercriminal actor Exilware. Compiled into native Windows executables, it establishes persistent access and profiles compromised hosts for resale through Exilware's Infected Marketplace. BraZetsu performs extensive system, process, software, network-service, active-window, browser-history, and business-environment reconnaissance, with particular interest in banking, ERP, e-commerce, industrial/SCADA, security, backup, healthcare, logistics, and law-enforcement environments. It collects Chromium-browser history, Brazilian CNAB financial-remittance files, and digital certificates; captures screenshots; executes remote shell commands; and can deploy additional worker modules. It uses encrypted dead-drop configuration retrieval and persistent WebSocket-over-TLS command-and-control communications. Later variants emphasized Brazilian corporate ERP and financial environments. Activity has primarily affected Brazil and broader Iberian and Latin American organizations. BraZetsu is assessed to be the same framework as AgenteV2.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Initial Access
- Persistence
- Post Exploitation
- Reconnaissance
- Scanning
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK