Affected Systems
Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera. Organizations using Brazilian CNAB financial file format at elevated risk.
Exploitation Status
Active exploitation confirmed since February 2026. BraZetsu framework operational since May 2026. Threat actor (Exilware) operates "Infected Marketplace" (infect[.]online) selling compromised host access for $5.80 initial deposit. Some samples fully undetected on VirusTotal at time of analysis. Delivery mechanism likely social engineering via phishing.
Business Impact
BraZetsu enables access-as-a-service model where compromised systems are cataloged and sold to secondary threat actors. Framework performs deep reconnaissance, extracts browser histories, digital certificates, and Brazilian CNAB financial remittance files. Maintains persistent WebSocket communication with command infrastructure. Buyers can remotely deploy secondary payloads without establishing initial foothold. Related tool CNABHunter rewrites CNAB files to redirect payments to attacker-controlled accounts. AI-enhanced data triage prioritizes high-value targets. Creates persistent threat-multiplier effect across regional ecosystem.
Urgency
🟠Within 24 hours
Recommended Actions
- Block known distribution domain caixaentradas1inboxshop[.]site and infect[.]online marketplace infrastructure at perimeter and DNS level
- Monitor for unauthorized WebSocket connections from endpoints, particularly to suspicious external domains
- Implement file integrity monitoring on directories containing CNAB financial files and alert on unauthorized modifications
- Hunt for Python-based executables masquerading as Microsoft Edge or other legitimate browsers in user directories
- Review browser extension installations and digital certificate stores on endpoints for unauthorized additions, focusing on Chrome, Edge, Brave, Vivaldi, and Opera
- Deploy email security controls to block VBS and MSI attachments from external senders, particularly Portuguese-language phishing targeting Iberian and Latin American users
- Enable EDR behavioral detection for screen capture activity, bulk browser history extraction, and systematic directory scanning for financial files
