translated Anatomía de BraZetsu: Cómo los cibercriminales abastecen el ecosistema clandestino
Group-IB
·fetched 2 Oct 2026, 11:33 UTC
Research
Why readDetails BraZetsu, a modular Python-based Windows malware framework used by Initial Access Brokers targeting Latin America and Iberia.
Group-IB discovered BraZetsu, a Python-based framework attributed to the threat actor Exilware. Unlike standard infostealers, BraZetsu acts as a master toolkit for Initial Access Brokers to monetize compromised endpoints. It features modular architecture and evasion techniques that avoided detection on VirusTotal during analysis.
Indicators18
- Hashes
f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17 54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700 91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0 cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78 d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99 0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf 1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246 96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042 0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d 30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe 10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8
- Addresses
38[.]242[.]246[.]176
- Domains
caixaentradas1inboxshop[.]site caixaentradas1boxshop[.]site c2[.]installscenter[.]com infect[.]online installscenter[.]com
group-ib.com → (opens in a new tab)