Group-IB detailed BraZetsu, a modular malware framework that turns compromised Windows machines into products sold to other criminals. It uses generative AI to triage stolen data and flag high-value victims for initial-access brokers, and it collects digital certificates, browser histories from several browsers, and financial files while watching users through screenshots. Compromised hosts feed an underground access-as-a-service marketplace where buyers can pay a small deposit to purchase entry into a victim's system and then run their own follow-on payloads. Some samples were fully undetected by antivirus at the time of analysis. It shows attackers using AI to scale the triage and resale of stolen access.
Symantec and Zscaler detailed Mistic, a stealthy new Windows backdoor used in intrusions since April and tied to KongTuke, an initial access broker that sells footholds to ransomware crews including Qilin, Akira, and Rhysida. Mistic is side-loaded through a legitimate Microsoft executable and a malicious DLL named to mimic endpoint-security software, runs payloads only in memory with nothing written to disk, and includes a self-delete kill switch, all aimed at long-term, low-visibility access. It is delivered through social-engineering lures such as fake CAPTCHAs and Microsoft Teams help-desk pretexts that trick users into running PowerShell commands. Defenders should watch for the unusual DLL side-loading pattern.