Skip to content

BraZetsu

BraZetsu is a Python-based Windows backdoor and initial-access-broker framework attributed with high confidence to the Brazilian cybercriminal actor Exilware.

Profile source: Mallory opens in a new tab

BraZetsu

Family profile

BraZetsu is a Python-based Windows backdoor and initial-access-broker framework attributed with high confidence to the Brazilian cybercriminal actor Exilware. Compiled into native Windows executables, it establishes persistent access and profiles compromised hosts for resale through Exilware's Infected Marketplace. BraZetsu performs extensive system, process, software, network-service, active-window, browser-history, and business-environment reconnaissance, with particular interest in banking, ERP, e-commerce, industrial/SCADA, security, backup, healthcare, logistics, and law-enforcement environments. It collects Chromium-browser history, Brazilian CNAB financial-remittance files, and digital certificates; captures screenshots; executes remote shell commands; and can deploy additional worker modules. It uses encrypted dead-drop configuration retrieval and persistent WebSocket-over-TLS command-and-control communications. Later variants emphasized Brazilian corporate ERP and financial environments. Activity has primarily affected Brazil and broader Iberian and Latin American organizations. BraZetsu is assessed to be the same framework as AgenteV2.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Scanning

Reported operators

Threat actors

1 named in public reporting
Exilware

BraZetsu est un framework malveillant Python, compilé avec Nuitka, attribué à Exilware. Group-IB établit avec haute confiance que BraZetsu et AgenteV2 sont le même framework.

MITRE ATT&CK

BraZetsu in ATT&CK

33 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.