Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure
What happened
Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. What they found is that the infrastructure had already moved on, quietly, months before anyone wrote about it.
Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether the published indicators still held up against its own certificate data.
BraZetsu is an initial access broker tool that breaks into Windows machines, checks them for ERP software, SCADA traces, EDR products, and certificate files, then packages the information for sale. The group behind it, called Infected Marketplace, charges a deposit of about 5.80 Brazilian reais to let buyers browse the listings.
Key facts
- What they — found: is that the infrastructure had already moved on, quietly, months before anyone wrote about it
Sources & evidence
- Security Affairs Reporting source
Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure ↗
https://securityaffairs.com/200634/cyber-crime/hunt-io-finds-new-brazetsu-infrastructure-months-before-disclosure.html