AI-enhanced malware turns hacked Windows machines into marketplace inventory
Group-IB detailed BraZetsu, a modular malware framework that turns compromised Windows machines into products sold to other criminals. It uses generative AI to triage stolen data and flag high-value victims for initial-access brokers, and it collects digital certificates, browser histories from several browsers, and financial files while watching users through screenshots. Compromised hosts feed an underground access-as-a-service marketplace where buyers can pay a small deposit to purchase entry into a victim's system and then run their own follow-on payloads. Some samples were fully undetected by antivirus at the time of analysis. It shows attackers using AI to scale the triage and resale of stolen access.
- Check
- Treat any infostealer infection as a potential gateway that could be resold, respond by fully rebuilding and rotating credentials, and hunt for stealthy data collection, browser theft, and unauthorized remote access.
- Affected
- Windows users infected by this framework; it harvests certificates, browser data, and financial files, uses AI to rank victims for brokers, and enrolls the machine into a resale marketplace.
- Fix
- Strengthen endpoint detection and application control, enforce phishing-resistant authentication so stolen credentials are less useful, monitor for stealthy collection and remote access, and rebuild rather than clean machines suspected of infostealer compromise.