Exilware runs an access-as-a-service marketplace for compromised hosts
Threat Actor Meta
Summary
Hide ▲
Show ▼
Exilware is operating an access-as-a-service marketplace that monetizes compromised hosts and lets buyers purchase footholds, expanding downstream payload execution across victim systems.
Related Happenings
BraZetsu Windows malware framework powering Infected Marketplace access sales
Malware Activity
H score23
First: 03.09.2026 18:26
Last: 03.09.2026 18:26
Sources 1
How related:
BraZetsu forms the foundation for the Infected Marketplace (aka "Banco de Infects", "infect[.]online"), a platform where the threat actor monetizes initial access to compromised hosts for an initial deposit of roughly $5.80.
About this happening:
The disclosure of BraZetsu shows a Python-based Windows malware framework being used to turn compromised hosts into tradable access inventory, increasing the value of...
BraZetsu Windows malware framework powering Infected Marketplace access sales
Malware ActivityHow related: BraZetsu forms the foundation for the Infected Marketplace (aka "Banco de Infects", "infect[.]online"), a platform where the threat actor monetizes initial access to compromised hosts for an initial deposit of roughly $5.80.
About this happening: The disclosure of BraZetsu shows a Python-based Windows malware framework being used to turn compromised hosts into tradable access inventory, increasing the value of...
Timeline
-
03.09.2026 18:26 1 articles · 3h ago
Exilware is first identified as its toolset evolves into an AI-assisted access broker
Initial DisclosureExilware is first identified on February 2, 2026 as its toolset rapidly evolves from a basic remote access trojan into a more capable framework for monetizing access to compromised hosts.
Show sources
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory — thehackernews.com — 03.09.2026 18:26
-
03.09.2026 18:26 1 articles · 3h ago
Earliest BraZetsu variant is dated to February 9, 2026
Campaign Scope UpdateThe earliest BraZetsu variant is dated to February 9, 2026, marking the first detected iteration of the Python-based Windows malware framework that would later underpin the Infected Marketplace.
Show sources
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory — thehackernews.com — 03.09.2026 18:26
-
03.09.2026 18:26 2 articles · 3h ago
Researchers disclose BraZetsu as a marketplace-enabling Windows malware framework
Technical Analysis UpdateCybersecurity researchers publicly disclose BraZetsu on September 3, 2026 as a Python-based Windows malware framework that turns compromised Windows hosts into tradable assets and supports an access-as-a-service marketplace for secondary criminals. The disclosure says the operation targets Iberian and Latin American organizations and uses generative AI for triage and target prioritization.
Show sources
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory — thehackernews.com — 03.09.2026 18:26
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory — thehackernews.com — 03.09.2026 18:26