Exilware
sigil
Exilware is a Brazilian threat actor operating the "Infect Marketplace," which commercializes access to compromised systems using the BraZetsu malware framework. BraZetsu employs a modular architecture and AI-driven reconnaissance to optimize target value across various sectors, including banking and government systems. The actor maintains a controlled operational model, requiring customers to spend quickly to limit exposure and risk. Exilware's activities reflect a sophisticated Initial Access Broker operation, transforming compromised systems into commercial assets through automated intelligence gathering.
Track Exilware on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.