hunt.io Hunt.io Discovers BraZetsu Access Broker Infrastructure Pre-Disclosure
Article Content
- •Hunt.io traced BraZetsu's infrastructure, revealing it had shifted months before public disclosure.
- •BraZetsu is a Python-based access broker targeting Windows systems, linked to the Brazilian actor Exilware.
- •The tool is sold on the Infected Marketplace, allowing buyers to exploit already compromised machines.
Hunt.io has identified new infrastructure associated with the BraZetsu access broker, which was first detailed by Group-IB on August 31, 2026. This access broker, linked to the Brazilian actor Exilware, utilizes a Python framework to infiltrate Windows machines and target ERP software and other sensitive data. The infrastructure was found to have moved on months before the public disclosure, indicating a proactive approach by the operators. Hunt.io's analysis focused on TLS certificate data, revealing that the command server hostname had been active on a second server since April 4, 2026. The BraZetsu tool is sold on the Infected Marketplace for a deposit of 5.80 Brazilian reais, allowing buyers to access already compromised machines. The findings highlight the challenges of tracking evolving cybercriminal infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track BraZetsu in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is BraZetsu?
How does the BraZetsu tool operate?
What should organizations do to protect themselves?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…