Skip to content
skopnix
← adversaries
Unknown · assessed origin Brazil

Exilware

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

Exilware is a Brazilian threat actor operating the "Infect Marketplace," which commercializes access to compromised systems using the BraZetsu malware framework. BraZetsu employs a modular architecture and AI-driven reconnaissance to optimize target value across various sectors, including banking and government systems. The actor maintains a controlled operational model, requiring customers to spend quickly to limit exposure and risk. Exilware's activities reflect a sophisticated Initial Access Broker operation, transforming compromised systems into commercial assets through automated intelligence gathering.

Take it with you
References
Early access

Track Exilware on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected