Threat Summary
Three concurrent OTX pulses published on 2026-10-05 reveal a maturing criminal supply chain focused on converting compromised endpoints into monetizable access and stolen credentials. The common thread is industrialized initial access and credential harvesting delivered through three distinct but complementary vectors:
-
BraZetsu — a Python-based Windows malware framework attributed to the Brazilian actor Exilware, purpose-built for Initial Access Broker (IAB) operations. Rather than simply stealing data, BraZetsu profiles, stages, and packages compromised systems for resale on underground marketplaces. It leverages WebSocket-based C2, AI-enhanced reconnaissance, CNAB file targeting (Brazilian banking interbank format), and companion malware families including CNABHunter, Ousaban, and AgenteV2. Targeting spans Finance, Government, Healthcare, Energy, Defense, and Telecom across the US, Brazil, Argentina, Paraguay, Portugal, and Spain — with the reference infrastructure
infect.onlinefunctioning as an infected-system marketplace. -
Psychedelic Stealer — an unattributed Russian-speaking operation that compromised at least six legitimate Ukrainian small-business websites between September 9–14, 2026. Victims were shown a fake Cloudflare CAPTCHA page using the ClickFix social-engineering technique, which instructs users to paste and run
msiexec.execommands via the Windows Run dialog. The campaign achieved a striking 14% completion rate (79 infections from 426 clicks), delivering an MSI payload that installs a malicious browser extension with a native-messaging bridge for cryptocurrency theft and credential harvesting. -
GlassWorm VS Code extensions — a supply-chain cluster spanning both the VS Code Marketplace and Open VSX registries. Malicious themes (Aurora Nocturne Night Theme, Cosmic Nebula Themes) act as staged loaders: downloading threat-actor-controlled batch files, decrypting embedded JavaScript, performing Russian-language geofencing, and using dead-drop resolvers to retrieve C2 configuration. The campaign targets developer environments — a direct path to source code, cloud credentials, SSH keys, and Solana cryptocurrency wallets.
Collective assessment: Credential and access theft is being productized. BraZetsu turns victims into sellable assets, ClickFix removes the exploit requirement by making the victim the installer, and GlassWorm poisons the developer toolchain itself. Organizations should assume that any successful execution of these chains results in full credential compromise and imminent resale of access.
Threat Actor / Malware Profile
BraZetsu (Exilware)
- Distribution: IAB-oriented delivery; compromised systems are inventoried and listed via
infect.online-branded marketplace infrastructure. Companion payloads: CNABHunter (Brazilian CNAB banking file theft), Ousaban (Latin American banking malware lineage), AgenteV2. - Payload behavior: Modular Python framework on Windows. AI-enhanced reconnaissance profiles the victim (industry, access level, financial data presence) to price the asset for resale.
- C2: WebSocket-based C2 — persistent full-duplex channels that blend with legitimate web traffic and evade simple HTTP inspection.
- Persistence/evasion: Advanced evasion techniques; modular staging limits on-disk footprint; Python runtime abuse complicates signature detection.
Psychedelic Stealer
- Distribution: Watering-hole compromise of legitimate Ukrainian SMB sites serving a fake Cloudflare verification page. ClickFix lures instruct victims to press Win+R and execute
msiexec.exeagainst attacker URLs (e.g.,https://uasputnik.com/elita.msi). - Payload behavior: MSI (
elita.msi) →psychedeliclove.exe→ malicious browser extension communicating through a native-messaging bridge to exfiltrate credentials and cryptocurrency wallet data. - C2: Domains
uasputnik.com,fsputnik.com; IPv4193.178.159.128; staging at107.175.82.242:9000. - Persistence: Browser extension installation provides durable, browser-level persistence that survives most host cleanups if the extension is not removed.
GlassWorm Extension Cluster
- Distribution: Supply-chain poisoning of VS Code Marketplace and Open VSX via malicious theme extensions (Aurora Nocturne Night Theme, Cosmic Nebula Themes).
- Payload behavior: Staged loader decrypts embedded JavaScript; Russian-language gating (execution suppressed on Russian-locale systems); downloads and executes attacker-controlled batch files from
fingercakes4sale.storeandholiday-themes.dev. - C2/dead drop: Dead-drop resolver pattern — extension fetches current C2 configuration from benign-looking infrastructure, complicating takedown and static blocklists.
- Objective: Credential theft from developer environments (cloud tokens, git credentials, API keys) and Solana wallet draining.
IOC Analysis
The pulses contain four operational indicator classes:
- Domains (
infect.online,uasputnik.com,fsputnik.com,fingercakes4sale.store,holiday-themes.dev): High-value for DNS sinkholing and proxy blocks.infect.onlinedoubles as marketplace infrastructure — any resolution indicates a compromised, potentially already-resold host. The.storeand.devTLDs used by GlassWorm infrastructure warrant newly-registered-domain (NRD) alerting. - IPv4 (
193.178.159.128,107.175.82.242): Block at egress; note the:9000non-standard port on the staging server — monitor for high-port HTTP downloads. - URLs (
https://uasputnik.com/elita.msi,http://107.175.82.242:9000/wilow/psychedeliclove.exe,https://fingercakes4sale.store/dsyuC): These are delivery URLs — hunt for them in proxy/Zscaler logs, EDR network events, and browser history to identify victims who clicked but were blocked (14% completion rate means most clicks need follow-up). - File hashes (MD5/SHA1/SHA256 across all three pulses): Push into EDR block lists and retro-hunt. Prioritize the SHA256 values for Psychedelic and GlassWorm loaders; treat MD5s as secondary for sandbox pivots.
Operationalization: Ingest via TAXII/STIX-capable TIP (OpenCTI, MISP, Anomali) or direct OTX API subscription to the pulse IDs. For WebSocket C2 (BraZetsu), enable TLS-inspection-aware detections or JA3/JA4 fingerprinting, since domain-only blocking is insufficient against persistent socket channels.
Detection Engineering
---
title: ClickFix-Style Manual msiexec Execution via Run Dialog
description: Detects user-initiated msiexec execution against remote URLs, consistent with fake-CAPTCHA ClickFix campaigns such as Psychedelic Stealer
status: experimental
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: windows
detection:
selection_msiexec:
Image|endswith: '\msiexec.exe'
selection_remote:
CommandLine|contains:
- 'http://'
- 'https://'
selection_parent:
ParentImage|endswith:
- '\explorer.exe'
- '\cmd.exe'
- '\powershell.exe'
condition: selection_msiexec and selection_remote and selection_parent
falsepositives:
- Legitimate enterprise software distribution via URL (rare; typically uses Intune/SCCM instead)
level: high
tags:
- attack.execution
- attack.t1204
- attack.t1218.007
date: 2026/10/05
---
title: WebSocket-Based C2 Communication Pattern (BraZetsu)
description: Detects Python processes establishing outbound WebSocket connections to non-standard ports, consistent with BraZetsu WebSocket C2
status: experimental
author: Security Arsenal Threat Intelligence
logsource:
category: network_connection
product: windows
detection:
selection_python:
Image|endswith:
- '\python.exe'
- '\pythonw.exe'
- '\py.exe'
selection_ports:
DestinationPort:
- 9000
- 8080
- 8443
- 4443
filter_corporate:
DestinationIp|startswith:
- '10.'
- '172.16.'
- '192.168.'
condition: selection_python and selection_ports and not filter_corporate
falsepositives:
- Legitimate Python development tooling and package installs
level: medium
tags:
- attack.command_and_control
- attack.t1071.001
- attack.t1572
date: 2026/10/05
---
title: VS Code Extension Staged Loader Activity (GlassWorm)
description: Detects VS Code or Node.js child processes spawning batch files or making outbound connections, consistent with GlassWorm malicious extension loaders
status: experimental
author: Security Arsenal Threat Intelligence
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\Code.exe'
- '\node.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
selection_suspicious_cmd:
CommandLine|contains:
- '.bat'
- 'Invoke-WebRequest'
- 'curl '
- 'DownloadString'
condition: selection_parent and selection_child and selection_suspicious_cmd
falsepositives:
- Legitimate extension build tasks and developer automation scripts
level: high
tags:
- attack.execution
- attack.t1195.002
- attack.t1059
date: 2026/10/05
// Hunt for Psychedelic Stealer ClickFix execution and C2, BraZetsu marketplace beaconing, and GlassWorm infrastructure
let malicious_domains = dynamic(["infect.online", "uasputnik.com", "fsputnik.com", "fingercakes4sale.store", "holiday-themes.dev"]);
let malicious_ips = dynamic(["193.178.159.128", "107.175.82.242"]);
let network_hits = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (malicious_domains) or RemoteIP in (malicious_ips)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, RemoteUrl, RemoteIP, RemotePort;
let clickfix_exec = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName =~ "msiexec.exe"
| where ProcessCommandLine has_any ("http://", "https://")
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName;
let python_ws = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName has_any ("python.exe", "pythonw.exe")
| where RemotePort in (9000, 8080, 8443, 4443)
| where not(RemoteIP startswith "10." or RemoteIP startswith "192.168.")
| project TimeGenerated, DeviceName, InitiatingProcessCommandLine, RemoteIP, RemotePort;
union network_hits, clickfix_exec, python_ws
| sort by TimeGenerated desc
# Security Arsenal IOC Hunt — BraZetsu / Psychedelic / GlassWorm
# Run elevated across endpoints via your RMM or EDR live response
$results = @()
# 1. Network connections to known C2 / staging infrastructure
$suspectIPs = @('193.178.159.128','107.175.82.242')
$suspectDomains = @('infect.online','uasputnik.com','fsputnik.com','fingercakes4sale.store','holiday-themes.dev')
$conns = Get-NetTCPConnection -ErrorAction SilentlyContinue | Where-Object { $suspectIPs -contains $_.RemoteAddress }
foreach ($c in $conns) {
$proc = Get-Process -Id $c.OwningProcess -ErrorAction SilentlyContinue
$results += [PSCustomObject]@{Check='C2 Connection'; Detail="$($proc.ProcessName) -> $($c.RemoteAddress):$($c.RemotePort)"; Host=$env:COMPUTERNAME}
}
# 2. DNS cache check for malicious domains
$dns = Get-DnsClientCache -ErrorAction SilentlyContinue | Where-Object {
$n = $_.Name; $suspectDomains | Where-Object { $n -like "*$_*" }
}
foreach ($d in $dns) { $results += [PSCustomObject]@{Check='DNS Cache Hit'; Detail=$d.Name; Host=$env:COMPUTERNAME} }
# 3. Known file hashes on disk (Psychedelic / GlassWorm samples)
$suspectHashes = @(
'06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90',
'38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878',
'a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07',
'5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268'
)
$scanPaths = @("$env:TEMP","$env:USERPROFILE\Downloads","$env:APPDATA","$env:LOCALAPPDATA")
foreach ($p in $scanPaths) {
Get-ChildItem -Path $p -Recurse -File -Include *.exe,*.msi,*.bat -ErrorAction SilentlyContinue | ForEach-Object {
$h = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
if ($suspectHashes -contains $h) {
$results += [PSCustomObject]@{Check='Malicious File'; Detail="$($_.FullName) [$h]"; Host=$env:COMPUTERNAME}
}
}
}
# 4. VS Code extension persistence — enumerate installed extensions
$extPath = "$env:USERPROFILE\.vscode\extensions"
if (Test-Path $extPath) {
Get-ChildItem $extPath -Directory -ErrorAction SilentlyContinue | Where-Object {
$_.Name -match 'aurora|nebula|cosmic|nocturne'
} | ForEach-Object {
$results += [PSCustomObject]@{Check='Suspicious VS Code Extension'; Detail=$_.FullName; Host=$env:COMPUTERNAME}
}
}
# 5. Scheduled tasks referencing dropped scripts or Python payloads
Get-ScheduledTask -ErrorAction SilentlyContinue | Where-Object {
($_.Actions.Execute -match 'python|msiexec|cmd') -and
($_.Actions.Arguments -match 'http|\.bat|Temp')
} | ForEach-Object {
$results += [PSCustomObject]@{Check='Suspicious Scheduled Task'; Detail="$($_.TaskName): $($_.Actions.Execute) $($_.Actions.Arguments)"; Host=$env:COMPUTERNAME}
}
$results | Format-Table -AutoSize
$results | Export-Csv -Path ".\otx_hunt_$env:COMPUTERNAME.csv" -NoTypeInformation
Write-Host "[+] Hunt complete. $($results.Count) findings exported."
Response Priorities
Immediate (0–4 hours)
- Block all listed domains and IPs at DNS, proxy, and egress firewall:
infect.online,uasputnik.com,fsputnik.com,fingercakes4sale.store,holiday-themes.dev,193.178.159.128,107.175.82.242(including port 9000). - Push all pulse file hashes into EDR block lists and run retro-hunts across a minimum 30-day window.
- Execute the KQL query and PowerShell hunt across the fleet; any host resolving
infect.onlineshould be treated as an actively brokered asset — isolate immediately. - Audit installed VS Code extensions org-wide; remove Aurora Nocturne / Cosmic Nebula variants and alert on
Code.exespawning script interpreters.
24 Hours
- All three campaigns are credential-stealing. For any confirmed or suspected execution, force enterprise-wide credential resets for the affected user: domain, email, VPN, cloud consoles, and SaaS sessions. Revoke active tokens and refresh sessions.
- Reset credentials stored in browsers on affected endpoints, and rotate any developer secrets (git tokens, cloud API keys, SSH keys, CI/CD secrets) present on hosts with malicious extensions.
- Review cryptocurrency wallet exposure for affected users (Psychedelic and GlassWorm both target crypto assets, including Solana).
- Contact users who visited the compromised Ukrainian sites or clicked ClickFix lures — the 14% completion rate means blocked-click users still need verification they did not self-execute.
1 Week
- Neutralize ClickFix as a technique: implement application control (WDAC/AppLocker) blocking user-context
msiexec.exeagainst remote URLs, and consider disabling or constraining the Run dialog for standard users via GPO. - Harden the developer toolchain: enforce an allowlisted VS Code extension policy (or mirror via a curated internal registry), and alert on extension installs outside the approved set.
- Restrict outbound WebSocket and high-port traffic for non-browser processes; deploy JA4/TLS fingerprinting for persistent-socket C2 detection (BraZetsu).
- Brief finance and LATAM-facing business units on CNAB-targeting risk (CNABHunter) and validate segmentation between payment-file systems and general user endpoints.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.