Back to Intelligence

BraZetsu Access Broker Infrastructure Exposed: Hunting Nuitka-Compiled Python Malware and Persistent C2 Patterns

SA
Security Arsenal Team
October 9, 2026
12 min read

The most valuable lesson from Hunt.io's recent tracking of the BraZetsu access broker isn't a hash, an IP, or a domain — it's that infrastructure intelligence built on hosting patterns and TLS certificate data stayed actionable long after the published indicators of compromise (IOCs) went stale. Hunt.io traced BraZetsu's command-and-control (C2) footprint and identified new, previously unreported infrastructure months before it surfaced in public reporting. Meanwhile, Group-IB's August 31 writeup characterized BraZetsu as a Python framework compiled with Nuitka, attributing it with high confidence to a Brazilian threat actor tracked as Exilware.

Why does this matter to your SOC? Access brokers are the supply chain of ransomware. When an initial access broker (IAB) operates comfortably for months on infrastructure that hasn't been disclosed yet, the organizations buying that access — ransomware affiliates, data extortion crews — are already inside downstream victims. If your detection strategy ends at "ingest the IOC feed and alert on matches," you are structurally blind to exactly this class of adversary. This post breaks down the BraZetsu tradecraft, explains why pattern-based infrastructure hunting beat indicator-based tracking, and gives you detection content you can deploy today for Nuitka-compiled Python payloads and broker-style C2 behavior.

Technical Analysis

What BraZetsu Is

Based on Group-IB's research and Hunt.io's infrastructure analysis:

  • Framework type: Access broker tooling written in Python and compiled to native executables using Nuitka. This is a deliberate anti-analysis choice — Nuitka-compiled binaries defeat the trivial decompilation that works against PyInstaller, break many YARA signatures written for Python bytecode artifacts, and produce PE files that look generically "native" to shallow triage.
  • Attribution: High-confidence linkage to a Brazilian actor tracked as Exilware, consistent with the growing ecosystem of Portuguese-language initial access operations selling footholds into corporate environments.
  • Function: As an access broker framework, BraZetsu's role is to establish and maintain footholds — persistence, host reconnaissance, and C2 beaconing — then hand or sell that access to downstream operators.

The Infrastructure Lesson: Patterns Outlive IOCs

Hunt.io's core finding deserves emphasis: hosting patterns and certificate data remained useful after published IOCs became outdated. This is a recurring reality in infrastructure tracking:

  1. Indicators decay fast. Domains get burned, IPs rotate, hashes change with every recompile. An actor recompiling a Nuitka binary generates a new hash instantly — hash-based detection has a shelf life measured in hours.
  2. Operational habits decay slowly. Actors reuse hosting providers with lax abuse desks, reuse certificate issuance patterns (same CA, similar subject/SAN structures, self-signed certs with characteristic fields), reuse port/service fingerprints, and reuse registration or naming conventions. These behavioral fingerprints survive infrastructure rotation.
  3. Certificate transparency is a defender's telescope. TLS certificate metadata — issuer patterns, SAN lists, certificate lifetimes, JA3/JA4 fingerprints of the listening service — lets you pivot from one known-bad node to the rest of the cluster, often before the actor ever uses it against a victim.

This is precisely how Hunt.io found new BraZetsu infrastructure months ahead of disclosure: pivots on hosting provider clustering and certificate characteristics, not on static blocklists.

Endpoint Observable: Nuitka-Compiled Payloads

Even when you can't see the C2, the payload leaves artifacts. Nuitka onefile-compiled executables have recognizable runtime behavior:

  • Onefile extraction: Nuitka onefile binaries self-extract to temporary directories following the pattern %TEMP%\onefile_<pid>_<random> and spawn child processes from that extracted path.
  • Environment marker: The NUITKA_ONEFILE_PARENT environment variable is set on child processes spawned from onefile bundles.
  • Unsigned, anomalous provenance: These binaries are almost never code-signed, typically appear with innocuous-sounding filenames (updates, installers, document-themed lures), and execute from user-writable paths (%APPDATA%, %LOCALAPPDATA%, %TEMP%, %PUBLIC%).
  • Network behavior: Short-interval beaconing from a process with no parent-child relationship to a browser or legitimate updater, frequently over 443 to recently registered or low-reputation hosting (bulletproof VPS providers rather than mainstream cloud).

Exploitation Status

There is no CVE here — this is crimeware tooling, not a vulnerability. BraZetsu is an actively operating access broker framework as of early 2026, with live infrastructure identified by Hunt.io ahead of public disclosure. Treat this as a confirmed in-the-wild threat, not a theoretical one. Because broker access feeds ransomware and extortion operations, the risk window between initial compromise and downstream impact can be days to weeks — detection at the broker stage is your cheapest interception point.

Detection & Response

The detections below target the durable behaviors: Nuitka onefile execution artifacts, unsigned binaries beaconing from user-writable paths, and infrastructure-level pivots on certificate and hosting patterns.

YAML
---
title: Nuitka Onefile Compiled Python Payload Execution
id: 3f8c2a71-9b4e-4d6a-a1c2-7e5f9d0b8a34
status: experimental
description: Detects execution from Nuitka onefile extraction directories, characteristic of Python malware frameworks (e.g., BraZetsu) compiled with Nuitka in onefile mode. Legitimate software rarely runs from onefile_ temp paths.
references:
  - https://attack.mitre.org/techniques/T1027/
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/02/09
tags:
  - attack.defense_evasion
  - attack.t1027
  - attack.execution
logsource:
  category: process_creation
  product: windows
detection:
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\onefile_'
      - '\Temp\onefile_'
  filter_signed:
    - Signer: null
  condition: selection_path and not filter_signed
falsepositives:
  - Rare legitimate tools distributed as Nuitka onefile bundles (internal Python tooling)
level: high
---
title: Unsigned Executable in User Directory Initiating Outbound Beaconing
id: 8b1d4e62-2c7a-4f91-b3d5-6a0e8c1f2b47
status: experimental
description: Detects unsigned executables running from user-writable paths making outbound HTTPS connections to non-browser processes, consistent with access broker beaconing behavior such as BraZetsu C2 callbacks.
references:
  - https://attack.mitre.org/techniques/T1071.001/
  - https://attack.mitre.org/techniques/T1036/
author: Security Arsenal
date: 2026/02/09
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1036
logsource:
  category: network_connection
  product: windows
detection:
  selection:
    DestinationPort:
      - 443
      - 8443
      - 4443
    Image|contains:
      - '\AppData\Roaming\'
      - '\AppData\Local\Temp\'
      - '\Users\Public\'
      - '\ProgramData\'
  filter_browsers:
    Image|endswith:
      - '\msedge.exe'
      - '\chrome.exe'
      - '\firefox.exe'
      - '\brave.exe'
      - '\iexplore.exe'
  condition: selection and not filter_browsers
falsepositives:
  - Auto-updaters of legitimate user-installed software (Slack, Discord, Zoom updaters) — tune with a signer allowlist
level: medium
---
title: Reconnaissance Command Chain from Temp or Public Directory Parent
id: 5c9a3f18-7e2b-4d83-a6c1-9f0b2e4d7a56
status: experimental
description: Detects system reconnaissance commands (whoami, systeminfo, net, ipconfig) spawned by a parent process executing from temp or public directories, a common access broker host-profiling pattern before selling access.
references:
  - https://attack.mitre.org/techniques/T1033/
  - https://attack.mitre.org/techniques/T1082/
author: Security Arsenal
date: 2026/02/09
tags:
  - attack.discovery
  - attack.t1033
  - attack.t1082
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\Users\Public\'
      - 'onefile_'
  selection_child:
    Image|endswith:
      - '\whoami.exe'
      - '\systeminfo.exe'
      - '\ipconfig.exe'
      - '\net.exe'
      - '\net1.exe'
      - '\quser.exe'
      - '\nltest.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Software installers performing environment checks (low frequency when correlated with unsigned parents)
level: high

The following KQL hunts across endpoint process and network telemetry in Microsoft Sentinel/Defender. It chains the two strongest broker signals: user-writable execution paths and periodic outbound connections from non-browser processes.

KQL — Microsoft Sentinel / Defender
// Hunt: Access broker beaconing pattern — unsigned processes in user paths with periodic outbound connections
// Tables: DeviceProcessEvents + DeviceNetworkEvents (Defender), works in Sentinel with MDE connector
let Lookback = 7d;
let SuspiciousPaths = @"(\\AppData\\Local\\Temp\\|\\AppData\\Roaming\\|\\Users\\Public\\|onefile_)";
let SuspectProcs =
    DeviceProcessEvents
    | where TimeGenerated >= ago(Lookback)
    | where FileName matches regex SuspiciousPaths or FolderPath matches regex SuspiciousPaths
    | project DeviceId, DeviceName, ProcessId, FileName, FolderPath, SHA256, ProcessTime=TimeGenerated;
DeviceNetworkEvents
| where TimeGenerated >= ago(Lookback)
| where RemotePort in (443, 8443, 4443)
| where ActionType == "ConnectionSuccess"
| join kind=inner SuspectProcs on DeviceId, ProcessId=ProcessId
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated),
            ConnectionCount=count(), DistinctRemotes=dcount(RemoteIP),
            RemoteIPs=make_set(RemoteIP, 20), RemoteURLs=make_set(RemoteUrl, 20)
    by DeviceName, FileName, FolderPath, SHA256
| where ConnectionCount >= 10  // sustained beaconing, not a one-off updater hit
| sort by ConnectionCount desc;
KQL — Microsoft Sentinel / Defender
// Hunt: Nuitka onefile extraction artifacts via process telemetry (Sysmon/SecurityEvent 4688)
SecurityEvent
| where TimeGenerated >= ago(7d)
| where EventID == 4688
| where NewProcessName matches regex @"(?i)onefile_\d+_\d+"
   or CommandLine matches regex @"(?i)onefile_\d+_\d+"
| extend Parent = tostring(split(ParentProcessName, "\\")[-1]), Child = tostring(split(NewProcessName, "\\")[-1])
| summarize Executions=count(), DistinctUsers=dcount(Account), Commands=make_set(CommandLine, 10)
    by Computer, Parent, Child
| sort by Executions desc;

For incident scoping with Velociraptor, this VQL artifact sweeps the fleet for Nuitka onefile artifacts — both live processes running from extraction directories and residual extraction folders left on disk.

VQL — Velociraptor
-- Artifact: SecurityArsenal.Hunt.NuitkaBroker
-- Sweeps for Nuitka onefile-compiled payload artifacts (BraZetsu-class access broker tooling)

-- Part 1: Live processes executing from onefile extraction directories
LET live_procs = SELECT Pid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(?i)onefile_\\\\?[0-9]+_[0-9]+'
   OR CommandLine =~ '(?i)onefile_[0-9]+_[0-9]+'

-- Part 2: Residual onefile extraction directories under user temp paths
LET temp_artifacts = SELECT FullPath, Mtime, Size, IsDir
FROM glob(globs='C:/Users/*/AppData/Local/Temp/onefile_*')

-- Part 3: Unsigned executables in user-writable paths with active connections
LET suspicious_net = SELECT Pid, Name, Path, Status, Family, Type,
       Laddr.IP AS LocalIP, Laddr.Port AS LocalPort,
       Raddr.IP AS RemoteIP, Raddr.Port AS RemotePort
FROM netstat()
WHERE RemotePort in (443, 8443, 4443)
  AND Path =~ '(?i)(AppData\\\\(Local\\\\Temp|Roaming)|Users\\\\Public)'

SELECT * FROM live_procs
UNION ALL
SELECT NULL AS Pid, FullPath AS Name, NULL AS Exe, NULL AS CommandLine,
       NULL AS Username, Mtime AS CreateTime FROM temp_artifacts

Run this as a fleet-wide hunt. Any host returning rows in Part 1 or Part 3 warrants immediate triage: capture the binary, hash it, detonate it in a sandbox, and pull its network destinations for infrastructure pivoting.

Hardening and Verification Script

This PowerShell script performs three defensive actions on Windows endpoints: (1) scans for active Nuitka onefile artifacts and unsigned executables beaconing from user paths, (2) enables WDAC/AppLocker-style audit posture via Script Block Logging and process creation auditing, and (3) checks that command-line auditing is captured for the Sigma rules above.

PowerShell
#requires -RunAsAdministrator
# Security Arsenal - BraZetsu / Nuitka-compiled broker hunting & audit hardening
$report = @()

# 1) Sweep for live onefile extraction processes
$onefileProcs = Get-CimInstance Win32_Process | Where-Object {
    $_.ExecutablePath -match 'onefile_\d+_\d+' -or $_.CommandLine -match 'onefile_\d+_\d+'
}
foreach ($p in $onefileProcs) {
    $report += [pscustomobject]@{ Finding='LIVE_ONEFILE_PROCESS'; Detail="$($p.ProcessId): $($p.ExecutablePath)"; Action='ISOLATE_HOST' }
}

# 2) Find unsigned executables in user-writable paths with ESTABLISHED 443 connections
$conns = Get-NetTCPConnection -State Established | Where-Object { $_.RemotePort -in 443,8443,4443 }
foreach ($c in $conns) {
    $proc = Get-Process -Id $c.OwningProcess -ErrorAction SilentlyContinue
    if ($proc -and $proc.Path -match 'AppData\\(Local\\Temp|Roaming)|Users\\Public') {
        $sig = Get-AuthenticodeSignature -FilePath $proc.Path
        if ($sig.Status -ne 'Valid') {
            $report += [pscustomobject]@{ Finding='UNSIGNED_BEACON'; Detail="$($proc.Path) -> $($c.RemoteAddress):$($c.RemotePort)"; Action='CAPTURE_AND_TRIAGE' }
        }
    }
}

# 3) Ensure process creation auditing + command line capture is enabled (required for Sigma coverage)
$audit = (auditpol /get /subcategory:"Process Creation" 2>$null) -join ' '
if ($audit -notmatch 'Success') {
    auditpol /set /subcategory:"Process Creation" /success:enable | Out-Null
    $report += [pscustomobject]@{ Finding='AUDIT_FIX'; Detail='Enabled Process Creation auditing'; Action='DONE' }
}
$cmdline = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit' -Name ProcessCreationIncludeCmdLine_Enabled -ErrorAction SilentlyContinue
if (-not $cmdline -or $cmdline.ProcessCreationIncludeCmdLine_Enabled -ne 1) {
    Set-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit' -Name ProcessCreationIncludeCmdLine_Enabled -Value 1 -Type DWord
    $report += [pscustomobject]@{ Finding='AUDIT_FIX'; Detail='Enabled command-line inclusion in 4688 events'; Action='DONE' }
}

# 4) Ensure PowerShell Script Block Logging (catches Python->PS pivots common in broker hands-on activity)
$sbl = Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name EnableScriptBlockLogging -ErrorAction SilentlyContinue
if (-not $sbl -or $sbl.EnableScriptBlockLogging -ne 1) {
    New-Item 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Force | Out-Null
    Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -Name EnableScriptBlockLogging -Value 1 -Type DWord
    $report += [pscustomobject]@{ Finding='LOGGING_FIX'; Detail='Enabled PowerShell Script Block Logging'; Action='DONE' }
}

$report | Format-Table -AutoSize
if ($report | Where-Object { $_.Action -in 'ISOLATE_HOST','CAPTURE_AND_TRIAGE' }) {
    Write-Warning 'Active broker indicators found. Isolate affected hosts and begin IR scoping immediately.'
}

Infrastructure-Level Hunting (Beyond the Endpoint)

The Hunt.io finding is your cue to hunt where the actor actually lives:

  • Certificate pivots: Pull the TLS certificates from any confirmed C2 and search Certificate Transparency logs (crt.sh, Censys, Shodan) for matching issuer patterns, SAN structures, and self-signed certificate field reuse. Brokers recompiling payloads and rotating domains rarely rotate their cert issuance habits.
  • Hosting clustering: Enrich confirmed C2 IPs with ASN and provider data. Access brokers favor a small set of abuse-tolerant VPS providers. Alert on outbound connections from your network to those ASNs where the destination has no business justification and domain age is under 90 days.
  • Beacon regularity: In your proxy/firewall logs, look for fixed-interval connections (jitter < 15%) from single hosts to rare destinations over long windows — classic broker check-in behavior that IOC matching will never catch.

Remediation

  1. Block and pivot on confirmed infrastructure. Ingest indicators from the Group-IB BraZetsu writeup (August 31) and Hunt.io's published research into your blocklists — but treat them as a starting point. Pivot on certificate and hosting characteristics to enumerate adjacent infrastructure before it's used against you.
  2. Constrain user-writable execution. Deploy WDAC or AppLocker policies blocking unsigned executables from running in %APPDATA%, %LOCALAPPDATA%\Temp, and %PUBLIC%. This single control breaks the default execution model of Nuitka onefile payloads.
  3. Harden egress. Force outbound 443 through authenticated proxy with TLS inspection where legally permissible; alert on direct-to-IP HTTPS (no SNI) and connections to recently registered domains or known bulletproof hosting ASNs.
  4. Verify telemetry coverage. Run the PowerShell script above to confirm process creation auditing with command-line capture and Script Block Logging are enabled — without them, the Sigma rules in this post are blind.
  5. Threat-hunt retroactively. Run the KQL queries over the last 30–90 days. Access brokers dwell; a host that beaconed for six weeks before ransomware deployment looks identical to a host that's still waiting to be sold.
  6. Prepare the IR handoff. If you find broker-stage compromise, assume the access will be sold. Scope for persistence mechanisms, credential theft, and lateral movement now — don't wait for the ransomware affiliate to validate the finding for you.
  7. Feed intelligence back. Subscribe to Hunt.io's research feed and Group-IB reporting. Pattern-based infrastructure intelligence (certificates, hosting, fingerprints) belongs in your detections alongside IOCs, not as an afterthought.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.