Three OTX pulses published 2026-10-05 reveal a converging trend: financially motivated and criminally sophisticated operators are industrializing initial access and credential theft through three distinct but complementary vectors — a commercial Initial Access Broker (IAB) toolkit, social-engineering ClickFix delivery, and developer-tool supply chain compromise.
BraZetsu (attributed to Brazilian actor Exilware) is not a commodity infostealer. It is a Python-based Windows malware framework purpose-built for Initial Access Brokers — it converts compromised endpoints into packaged, sellable assets on underground marketplaces. It pairs with the CNABHunter module (targeting Brazilian CNAB banking file formats), the Ousaban banking malware lineage, and AgenteV2, and uses WebSocket-based C2 with AI-enhanced reconnaissance to profile victims for resale value. Targeting spans Finance, Government, Healthcare, Manufacturing, Technology, Retail, Energy, Telecom, Transportation, and Defense across the US, Brazil, Argentina, Paraguay, Portugal, and Spain.
Psychedelic Stealer is an unattributed Russian-speaking operation that compromised at least six legitimate Ukrainian small-business websites between September 9–14, 2026, injecting fake Cloudflare CAPTCHA pages. The ClickFix chain tricks victims into pasting msiexec.exe commands into the Windows Run dialog — achieving a 14% completion rate (79 infections from 426 clicks). The payload (psychedeliclove.exe) installs a malicious browser extension using a native-messaging bridge to steal cryptocurrency and browser credentials.
GlassWorm-linked extensions were found on both the VS Code Marketplace and Open VSX registries. Two confirmed malicious themes — Aurora Nocturne Night Theme (downloads and executes attacker-controlled batch files) and Cosmic Nebula Themes (staged loader that decrypts embedded JavaScript with Russian-language geofencing) — deliver credential theft and Solana cryptocurrency targeting through dead-drop resolver infrastructure.
Collectively these pulses show the access-for-sale economy maturing: IAB toolkits monetize intrusions, ClickFix bypasses perimeter controls via user execution, and IDE extensions implant persistence inside developer environments where secrets and signing keys live.
Threat Actor / Malware Profile
BraZetsu / Exilware (IAB Framework)
- Distribution: Underground marketplace sales; modular Python-based Windows framework bundled with CNABHunter and AgenteV2 modules.
- Payload behavior: Comprehensive host profiling (banking relationships, CNAB file artifacts, enterprise role of the victim) to price access for resale; AI-enhanced reconnaissance automates victim valuation.
- C2: WebSocket-based C2 channel (persistent, full-duplex, blends with legitimate web traffic); infrastructure includes
infect.online. - Persistence: Modular loader architecture allows staged module deployment post-compromise.
- Anti-analysis: Python packaging/obfuscation, modular design that withholds second-stage payloads until victim profiling completes.
Psychedelic Stealer (ClickFix / Fake CAPTCHA)
- Distribution: Compromised legitimate Ukrainian small-business sites serving fake Cloudflare verification pages.
- Payload behavior: User is socially engineered into running
msiexec.exevia Win+R, pullingelita.msifromuasputnik.com; the MSI dropspsychedeliclove.exeand a malicious browser extension communicating over a native-messaging bridge for cryptocurrency and credential theft. - C2: 193.178.159.128 and 107.175.82.242:9000 (
/wilow/psychedeliclove.exe); domainsuasputnik.com,fsputnik.com. - Anti-analysis: User-driven execution defeats email/web sandboxing; native-messaging bridge hides extension-to-host traffic from browser telemetry.
GlassWorm VS Code Extensions (Supply Chain)
- Distribution: Malicious themes published to VS Code Marketplace and Open VSX (Aurora Nocturne Night Theme, Cosmic Nebula Themes).
- Payload behavior: Staged JavaScript loader decrypted at runtime; downloads and executes batch files; credential theft with Solana wallet targeting; Russian-language gating (geofencing to avoid CIS-region execution — a classic Russian-speaking actor marker).
- C2 / Dead-drop:
fingercakes4sale.store(including/dsyuCpath) andholiday-themes.devused as staging/dead-drop resolvers. - Anti-analysis: Encrypted embedded JavaScript, staged decryption, language-based execution gating, abuse of trusted extension registries.
IOC Analysis
The pulses contain four indicator classes, each requiring different operational handling:
- File hashes (MD5/SHA1/SHA256): 54 BraZetsu indicators are predominantly hashes — bulk-load into your EDR blocklist and retro-hunt. Note MD5/SHA1 dominance suggests rapid payload recompilation; prioritize behavioral detections over hash whack-a-mole.
- Domains:
infect.online(BraZetsu C2),uasputnik.com/fsputnik.com(Psychedelic staging),fingercakes4sale.store/holiday-themes.dev(GlassWorm dead-drop). Block at DNS sinkhole and web proxy; alert on historical resolution via passive DNS. - IPv4:
193.178.159.128,107.175.82.242(Psychedelic C2/staging). Block at perimeter; note port 9000 usage — hunt egress on non-standard ports. - URLs: Full paths like
https://uasputnik.com/elita.msiandhttp://107.175.82.242:9000/wilow/psychedeliclove.exeenable precise proxy blocking and retro-search of proxy/Zeek http logs.
Operationalization: Export OTX pulses via the OTX DirectConnect API or TAXII feed into your TIP (MISP, OpenCTI, Anomali), then push to EDR (hash blocks), DNS firewall (domains), and NGFW (IPs/URLs). Use oletools, pestudio, and capa for static triage of matched samples; WebSocket C2 is best decoded from Zeek websocket.log or Suricata with the websocket keyword. MSI and VSIX artifacts should be detonated in an isolated sandbox (ANY.RUN, Joe Sandbox) with browser-extension instrumentation enabled.
Detection Engineering
---
title: ClickFix Fake CAPTCHA MSI Execution via Run Dialog
id: 9f2a1c4e-7b3d-4e5a-a1c2-psychedelic001
status: experimental
description: Detects msiexec.exe spawned from explorer.exe with remote URL payload delivery, consistent with Psychedelic Stealer ClickFix chain where victims paste msiexec commands into the Windows Run dialog.
author: Security Arsenal Threat Intel
date: 2026/10/05
references:
- https://connect.securonix.com/threat-research-intelligence-62/the-psychedelic-stealer-when-the-captcha-is-the-installer-582
logsource:
category: process_creation
product: windows
detection:
selection_msiexec:
Image|endswith: '\msiexec.exe'
ParentImage|endswith: '\explorer.exe'
selection_remote:
CommandLine|contains:
- 'http://'
- 'https://'
selection_iocs:
CommandLine|contains:
- 'uasputnik.com'
- 'fsputnik.com'
- 'elita.msi'
condition: selection_msiexec and (selection_remote or selection_iocs)
falsepositives:
- Rare legitimate user-driven MSI installs from URLs
level: high
tags:
- attack.execution
- attack.t1204
- attack.t1059
---
title: Malicious VS Code Extension Spawning Script Interpreter
id: 7c4d8e2f-1a5b-4c6d-b2e3-glassworm0002
status: experimental
description: Detects Visual Studio Code spawning cmd.exe, powershell.exe, or wscript/cscript — consistent with GlassWorm-linked malicious themes executing downloaded batch files and staged JavaScript loaders.
author: Security Arsenal Threat Intel
date: 2026/10/05
references:
- https://socket.dev/blog/glassworm-vscode-themes
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\Code.exe'
- '\code-insiders.exe'
- '\VSCodium.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\powershell_ise.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
filter_known_terminals:
CommandLine|contains:
- 'vscode'
- 'npm'
- 'node_modules'
condition: selection_parent and selection_child and not filter_known_terminals
falsepositives:
- Integrated terminal usage by developers; tune with user baseline
level: medium
tags:
- attack.execution
- attack.t1059
- attack.t1195
---
title: BraZetsu Python Malware WebSocket C2 Egress
id: 3e8f1a6b-9c2d-4f7e-c3d4-brazetsu0003
status: experimental
description: Detects Python runtime processes establishing outbound WebSocket connections or contacting known BraZetsu/Exilware C2 infrastructure, consistent with the IAB framework's WebSocket C2 channel.
author: Security Arsenal Threat Intel
date: 2026/10/05
references:
- https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace-es/
logsource:
category: network_connection
product: windows
detection:
selection_python:
Image|endswith:
- '\python.exe'
- '\pythonw.exe'
- '\py.exe'
selection_c2_domain:
DestinationHostname|contains:
- 'infect.online'
selection_ws_scheme:
Initiated: 'true'
condition: selection_python and selection_ws_scheme and selection_c2_domain
falsepositives:
- Legitimate Python applications using WebSockets; combine with hash reputation
level: critical
tags:
- attack.command_and_control
- attack.t1071
- attack.t1572
// Psychedelic Stealer + GlassWorm + BraZetsu combined hunt — Microsoft Sentinel
let c2Domains = dynamic(["infect.online","uasputnik.com","fsputnik.com","fingercakes4sale.store","holiday-themes.dev"]);
let c2IPs = dynamic(["193.178.159.128","107.175.82.242"]);
let iocHashes = dynamic(["06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90","38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878","a276b76d3b00f302bb4dfb3690125c85ff472b16049c3c37476ac5e51096df07","5e68ca8c2097caccdb74d2752b85b85595a4bf646b442b8431a2416e87dbf268","684c877a52d226d50584cb886ca8ec5bec6355d4de853f406734c79d5b387804","da2d950e50326171adbff9c2bfd6f28998e32623ea7c2c475b9159a45cfb86bb","0e00adb0a5ca285b838af623c753b6ff","1b6dd10ace5e6e9a5e52dbbbc5e45289","1f250eb486571d99bc1e4d760e37a554"]);
union isfuzzy=true
(DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (c2Domains) or RemoteIP in (c2IPs) or RemotePort == 9000
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, HitType="NetworkIOC"),
(DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where (FileName =~ "msiexec.exe" and ProcessCommandLine has_any ("http://","https://") and InitiatingProcessFileName =~ "explorer.exe")
or (SHA256 in (iocHashes) or MD5 in (iocHashes))
or (InitiatingProcessFileName has_any ("Code.exe","VSCodium.exe") and FileName has_any ("cmd.exe","powershell.exe","wscript.exe","mshta.exe") and ProcessCommandLine !has "node_modules")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256, MD5, HitType="ProcessBehavior"),
(DeviceFileEvents
| where TimeGenerated > ago(14d)
| where SHA256 in (iocHashes) or MD5 in (iocHashes) or FileName has_any ("psychedeliclove.exe","elita.msi")
| project TimeGenerated, DeviceName, FolderPath, FileName, SHA256, MD5, HitType="FileIOC")
| sort by TimeGenerated desc
# Security Arsenal — Tri-Campaign IOC Hunt (BraZetsu / Psychedelic / GlassWorm)
# Run elevated on Windows endpoints. Outputs CSV findings.
$report = @()
# 1) Psychedelic Stealer — malicious browser extension + native messaging manifests
$nmPaths = @(
"$env:LOCALAPPDATA\Google\Chrome\User Data\NativeMessagingHosts",
"HKLM:\SOFTWARE\Google\Chrome\NativeMessagingHosts",
"HKCU:\SOFTWARE\Google\Chrome\NativeMessagingHosts",
"HKLM:\SOFTWARE\Microsoft\Edge\NativeMessagingHosts"
)
foreach ($p in $nmPaths) {
if (Test-Path $p) {
Get-ChildItem $p -Recurse -ErrorAction SilentlyContinue | ForEach-Object {
$report += [PSCustomObject]@{Finding="NativeMessaging manifest"; Path=$_.FullName}
}
}
}
# Flag suspicious extensions installed outside Web Store flow
Get-ChildItem "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Extensions" -Directory -ErrorAction SilentlyContinue | ForEach-Object {
$manifest = Join-Path $_.FullName "*\manifest.json"
$m = Get-ChildItem $manifest -ErrorAction SilentlyContinue | Select-Object -First 1
if ($m -and (Select-String -Path $m.FullName -Pattern "nativeMessaging" -Quiet)) {
$report += [PSCustomObject]@{Finding="Extension w/ nativeMessaging permission"; Path=$_.FullName}
}
}
# 2) BraZetsu — python-based persistence via Run keys and scheduled tasks
$runKeys = @("HKCU:\Software\Microsoft\Windows\CurrentVersion\Run","HKLM:\Software\Microsoft\Windows\CurrentVersion\Run")
foreach ($rk in $runKeys) {
(Get-ItemProperty $rk -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object {
$_.Value -match "python|pyw?\.exe|infect\.online" } | ForEach-Object {
$report += [PSCustomObject]@{Finding="Suspicious Run key (Python/BraZetsu)"; Path="$rk -> $($_.Name) = $($_.Value)"}
}
}
Get-ScheduledTask | ForEach-Object {
$act = $_.Actions | Out-String
if ($act -match "python|msiexec.*http|infect\.online") {
$report += [PSCustomObject]@{Finding="Suspicious scheduled task"; Path="$($_.TaskName): $act"}
}
}
# 3) GlassWorm — malicious VS Code extensions
$extDirs = @("$env:USERPROFILE\.vscode\extensions","$env:USERPROFILE\.vscode-insiders\extensions")
$susThemes = @("aurora-nocturne","cosmic-nebula")
foreach ($d in $extDirs) {
if (Test-Path $d) {
Get-ChildItem $d -Directory | Where-Object {
$n = $_.Name.ToLower(); $susThemes | Where-Object { $n -like "*$_*" }
} | ForEach-Object { $report += [PSCustomObject]@{Finding="GlassWorm-linked extension"; Path=$_.FullName} }
}
}
# 4) Network IOCs — active/historical connections to C2
$c2 = @("infect.online","uasputnik.com","fsputnik.com","fingercakes4sale.store","holiday-themes.dev","193.178.159.128","107.175.82.242")
Get-NetTCPConnection -ErrorAction SilentlyContinue | Where-Object {
$c2 -contains $_.RemoteAddress -or $_.RemotePort -eq 9000 } | ForEach-Object {
$proc = (Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName
$report += [PSCustomObject]@{Finding="C2 connection"; Path="$($_.RemoteAddress):$($_.RemotePort) ($proc)"}
}
foreach ($dom in $c2) {
$r = Resolve-DnsName $dom -ErrorAction SilentlyContinue
if ($r) { $report += [PSCustomObject]@{Finding="DNS resolution of IOC domain"; Path="$dom -> $($r.IPAddress -join ',')"} }
}
$report | Format-Table -AutoSize
$report | Export-Csv ".\tri_campaign_hunt_$(Get-Date -Format yyyyMMdd_HHmm).csv" -NoTypeInformation
Write-Host "Hunt complete. Findings: $($report.Count)"
Response Priorities
Immediate (0–4 hours)
- Block all IOCs: Sinkhole
infect.online,uasputnik.com,fsputnik.com,fingercakes4sale.store,holiday-themes.dev; null-route193.178.159.128and107.175.82.242; block TCP/9000 egress; push all 77 file hashes to EDR blocklists. - Hunt for execution artifacts: Retro-search proxy logs for
.msidownloads from suspicious domains andmsiexecwith URL arguments; query EDR forCode.exespawning script interpreters; check DNS caches for the IOC domains. - Audit developer endpoints: Inventory installed VS Code/Open VSX extensions across the fleet; remove Aurora Nocturne Night Theme and Cosmic Nebula Themes immediately; check
%USERPROFILE%\.vscode\extensionsagainst publisher allowlists.
24 Hours
- Credential verification (all three campaigns steal or broker credentials): Force password resets for any user whose endpoint touched an IOC. Rotate browser-stored credentials, crypto wallet keys (especially Solana), and — critically for GlassWorm victims — any secrets, API tokens, SSH keys, or cloud credentials present in developer environments. Revoke active sessions/tokens.
- Access resale exposure check (BraZetsu): Because Exilware monetizes access via IAB channels, treat any confirmed BraZetsu infection as a pending ransomware or follow-on intrusion event. Assume internal reconnaissance data has been sold; hunt for lateral movement artifacts and newly created accounts.
- Browser extension forensics: On Psychedelic-affected hosts, enumerate Chrome/Edge extensions with
nativeMessagingpermissions and remove unauthorized entries.
1 Week
- ClickFix hardening: Deploy browser isolation or smart-screen policies blocking fake CAPTCHA verification pages; run user awareness focused specifically on "never paste commands into Win+R from a webpage."
- Extension governance: Implement VS Code extension allowlisting (policy-managed extensions or internal registry mirror); require code review for extension updates on developer workstations.
- MSI execution control: Restrict
msiexecvia AppLocker/WDAC to signed, approved packages; alert on MSI installs sourced from URLs. - Egress segmentation: Alert on workstations initiating WebSocket connections to uncategorized domains and on Python processes making outbound connections — a strong BraZetsu behavioral tripwire.
- Finance-sector LATAM controls: For organizations processing Brazilian CNAB payment files, add file-access monitoring on CNAB directories to detect CNABHunter-style enumeration.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.