Ethical Hacking News
Hunt.io, a cybersecurity research firm, has discovered that the BraZetsu access broker has moved its infrastructure to a new location just months before its public disclosure. The firm found that the new location had a stable pattern, including a naming convention and hosting pattern, which can be used to detect the broker's activities. The discovery highlights the importance of building detection rules based on patterns rather than IP addresses, and the need to handle infrastructure still potentially active after a public takedown report.
The BraZetsu access broker is a tool used to break into Windows machines and sell stolen data, and is operated by the group Infected Marketplace. The firm's discovery provides valuable insights into the tactics used by cybercriminals to maintain their infrastructure, and highlights the importance of responsible reporting and notification of relevant national CERTs.
The discovery also highlights the limitations of using hashes to detect malware, as they can rotate quickly and become useless as a long-term detection signal. Instead, detection rules should be based on patterns, such as naming conventions and hosting patterns.
Overall, the discovery by Hunt.io provides valuable insights into the tactics used by cybercriminals, and highlights the importance of responsible reporting and detection rules in the fight against cybercrime.
The BraZetsu access broker, a tool used to break into Windows machines, has moved its infrastructure to a new location just months before its public disclosure.The BraZetsu access broker's new infrastructure still follows a pattern, making it easier to detect.The key to detecting BraZetsu's infrastructure lies in its naming convention and hosting pattern, rather than the IP address.The BraZetsu group, Infected Marketplace, charges a deposit to buyers to browse listings, and buyers don't need to know how BraZetsu works.The researchers found that the command server hostname had already been using TLS on a second server since April 4, almost five months before the report was published.The original seed IP was used by Contabo from January to February, before switching to a new hostname.The BraZetsu group kept the same habits when moving providers, including the same hosting company and Hestia Control Panel setup.The real lesson from this discovery is that public takedown reports can be misleading, and it's essential to focus on patterns rather than specific IP addresses.
Hunt.io, a cybersecurity research firm, has made a remarkable discovery that sheds light on the tactics used by cybercriminals to maintain their infrastructure after a public takedown report. The firm has found that the BraZetsu access broker, a tool used to break into Windows machines and sell stolen data, has moved its infrastructure to a new location just months before its public disclosure.
The BraZetsu access broker is an initial access broker tool that breaks into Windows machines, checks them for ERP software, SCADA traces, EDR products, and certificate files, then packages the information for sale. The group behind it, called Infected Marketplace, charges a deposit of about 5.80 Brazilian reais to let buyers browse the listings. The buyer who later deploys ransomware or steals money from a bank account doesn’t need to know how BraZetsu works. They simply buy a machine that has already been compromised.
Hunt.io’s approach was narrow on purpose. Instead of reversing the binary again, they took the hostnames and IP address Group-IB had already published and ran them against their own TLS certificate inventory. The firm states, “The premise is narrow. An operator who keeps a panel and a command channel under the same apex, with Let’s Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month.”
The researchers found that the command server hostname mentioned in the August report, c2.installscenter.com, had already been using TLS on a second server since April 4, almost five months before the report was published. Researchers found it on the same IP address as the control panel hostname, painel.installscenter.com. Both were hosted by the same Swedish provider, Njalla.
The original seed IP, a Contabo server, tells its own story. From January through early February it served Contabo’s default factory hostname, boring and unremarkable. Then on February 11, right around when Group-IB dates the first BraZetsu version, the certificate switched to painel.seu-dominio.com, a Portuguese placeholder name literally meaning “your domain” lifted straight from hosting tutorials. That name showed up 17 separate times over five weeks, every two to four days, which is a strong signal of a panel someone actually kept running, not a page thrown up for one night.
When the operators eventually moved providers, they kept the exact same habits. The new host came alive on March 21, the very day the installscenter.com domain was registered, running the identical Hestia Control Panel setup with the same painel prefix. Different hosting company, same fingerprint.
The real lesson here isn’t about BraZetsu specifically, it’s about what actually survives a public takedown report. Hashes rotated across five different versions in just four months, useless as a long-term detection signal. What held steady from February through June was the naming convention and hosting pattern itself, a panel prefix on a nonstandard port, running on a VPS configured with Hestia Control Panel.
Hunt.io’s conclusion lands on a point worth remembering for anyone building detection rules off a threat intel report: don’t chase the IP of the month, chase the pattern. Before publishing, the researchers notified the relevant national CERTs and confirmed no victim data was recovered during the investigation, which is the responsible way to handle infrastructure still potentially active.
“The public reporting gave us three things to work from: the C2 hostname, the IP tied to it early in the year, and the shop both of them served. Our certificate inventory showed what happened to that hostname after the first VPS went quiet. It showed up on a new host in a different provider, with a control panel on the same apex.” concludes the report. “The TLS services on 80.78.27[.]252 went quiet after 20 June. The pattern is more stable: a painel. or c2. prefix on a port that isn’t 443, on a VPS running Hestia Control Panel. It held from February to June across two providers, and that’s what we’d build detection on, not the IP.”
Related Information:
https://www.ethicalhackingnews.com/articles/Huntio-Discovers-BraZetsu-Access-Brokers-New-Infrastructure-Before-Public-Disclosure-ehn.shtml
https://securityaffairs.com/200634/cyber-crime/hunt-io-finds-new-brazetsu-infrastructure-months-before-disclosure.html
Published: Thu Oct 8 15:50:14 2026 by llama3.2 3B Q4_K_M