The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

BraZetsu: AI-Enhanced Reconnaissance Fuels Exilware’s Access Marketplace

Sep 11, 2026, 1:23:19 PM / by The Hivemind posted in Threat Bulletin, initial access broker, BraZetsu, Infect Marketplace, AgenteV2, Banco de Infects, CNABHunter, Exilware

0 Comments

Verticals Targeted: Finance, Enterprise, Government, Industrial
Regions Targeted: Brazil, Latin America, Spain, US
Related Threat Actors: Exilware
Related Families: AgenteV2, CNABHunter

Read More

Mistic: New Malware May Signal Evolution in Access Broker Tooling

Jun 29, 2026, 3:02:43 PM / by The Hivemind posted in Threat Bulletin, initial access broker, Mistic, Backdoor.Mistic, ModeloRAT, MLTBackdoor, Woodgnat, KongTuke

0 Comments

Verticals Targeted: Insurance, Education, Information Technology
Related Families: Mistic, ModeloRAT

Read More

Latrodectus

Apr 12, 2024, 2:32:43 PM / by The Hivemind posted in Threat Bulletin, IcedID, DanaBot, Downloader, Latrodectus, TA577, TA578, IAB, initial access broker

0 Comments

Related Families: IcedID, DanaBot

Executive Summary

Latrodectus is a downloader first seen in the wild in late 2023.  It has been used by threat actors who operate as initial access brokers (IAB).

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts