HUNT [.]io traced BraZetsu’s infrastructure and found that hosting patterns and certificate data remained useful long after the original indicators of compromise (IOCs) had become outdated. Group-IB had previously described BraZetsu as a Python framework compiled with Nuitka linked to a Brazilian actor named Exilware, and Hunt[.]io verified that the infrastructure had moved on months before that description.
BraZetsu operates as an initial access broker: it compromises Windows machines, checks for ERP software and SCADA traces, assesses EDR products and certificate files, and then packages the data for sale. The operator group, Infected Marketplace, reportedly requires a small deposit to access listings, and the buyer who deploys ransomware or siphons funds does not need to understand BraZetsu’s inner workings.
Hunt[.]io adopted a focused approach: rather than reverse‑engineering the binary again, it cross‑checked Group-IB’s published indicators against its own TLS certificate inventory. The c2 hostnames, IPs and panel shop were still traceable even as IOs aged. Evidence shows the command server hostname c2.installscenter[.]com had been using TLS on a second server since 4 April, connected to painel.installscenter[.]com on the same IP, with both hosted by Njalla in Sweden.
The seed IP, a Contabo server, switched to painel.seu-dominio[.]com on 11 February and repeated the painel prefix on a new host after provider moves, suggesting operational continuity. The study notes that while hashes rotated across five versions in four months, the persistent pattern—painel or c2 prefixes on non‑443 ports on a Hestia Control Panel VPS—provided a more reliable detection signal. The researchers advised focusing on patterns rather than the IP and confirmed no victim data was recovered during the investigation.