Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure
Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure 2026-10-8 17:47:35 Author: securityaffairs.com(查看原文) 阅读量:7 收藏

Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure

Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated.

Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether the published indicators still held up against its own certificate data. What they found is that the infrastructure had already moved on, quietly, months before anyone wrote about it.

BraZetsu is an initial access broker tool that breaks into Windows machines, checks them for ERP software, SCADA traces, EDR products, and certificate files, then packages the information for sale.

The group behind it, called Infected Marketplace, charges a deposit of about 5.80 Brazilian reais to let buyers browse the listings. The buyer who later deploys ransomware or steals money from a bank account doesn’t need to know how BraZetsu works. They simply buy a machine that has already been compromised.

Hunt.io’s approach was narrow on purpose. Instead of reversing the binary again, they took the hostnames and IP address Group-IB had already published and ran them against their own TLS certificate inventory.

“We didn’t reverse the binary again. We took the published indicators and checked what our certificate inventory still shows.” Hunt.io states. “The premise is narrow. An operator who keeps a panel and a command channel under the same apex, with Let’s Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month.”

Binaries can change all the time. A hostname linked to a valid TLS certificate is much harder to replace.

That approach worked quickly. The command server hostname mentioned in the August report, c2.installscenter.com, had already been using TLS on a second server since April 4, almost five months before the report was published. Researchers found it on the same IP address as the control panel hostname, painel.installscenter.com. Both were hosted by the same Swedish provider, Njalla.

The original seed IP, a Contabo server, tells its own story. From January through early February it served Contabo’s default factory hostname, boring and unremarkable. Then on February 11, right around when Group-IB dates the first BraZetsu version, the certificate switched to painel.seu-dominio.com, a Portuguese placeholder name literally meaning “your domain” lifted straight from hosting tutorials. That name showed up 17 separate times over five weeks, every two to four days, which is a strong signal of a panel someone actually kept running, not a page thrown up for one night.

When the operators eventually moved providers, they kept the exact same habits. The new host came alive on March 21, the very day the installscenter.com domain was registered, running the identical Hestia Control Panel setup with the same painel prefix. Different hosting company, same fingerprint.

“Passive DNS helps explain it. Our records show c2.installscenter[.]com resolving to 80.78.27[.]252 between 22 and 26 March, and to Cloudflare (104.21.78.246, 172.67.138.224) from 26 March on.” states the report. “The only A record we have for painel.installscenter[.]com is Cloudflare, from 21 March.”

The real lesson here isn’t about BraZetsu specifically, it’s about what actually survives a public takedown report. Hashes rotated across five different versions in just four months, useless as a long-term detection signal. What held steady from February through June was the naming convention and hosting pattern itself, a panel prefix on a nonstandard port, running on a VPS configured with Hestia Control Panel.

Hunt.io’s conclusion lands on a point worth remembering for anyone building detection rules off a threat intel report: don’t chase the IP of the month, chase the pattern. Before publishing, the researchers notified the relevant national CERTs and confirmed no victim data was recovered during the investigation, which is the responsible way to handle infrastructure still potentially active.

“The public reporting gave us three things to work from: the C2 hostname, the IP tied to it early in the year, and the shop both of them served. Our certificate inventory showed what happened to that hostname after the first VPS went quiet. It showed up on a new host in a different provider, with a control panel on the same apex.” concludes the report. “The TLS services on 80.78.27[.]252 went quiet after 20 June. The pattern is more stable: a painel. or c2. prefix on a port that isn’t 443, on a VPS running Hestia Control Panel. It held from February to June across two providers, and that’s what we’d build detection on, not the IP.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, BraZetsu)




文章来源: https://securityaffairs.com/200634/cyber-crime/hunt-io-finds-new-brazetsu-infrastructure-months-before-disclosure.html
如有侵权请联系:admin#unsafe.sh