< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Cybercrime evolves through AI integration and standardized attack playbooks

The cybercrime landscape in 2026 is characterized by the integration of generative artificial intelligence and the industrialization of attack methodologies. Threat actors are utilizing AI throughout the attack lifecycle, including reconnaissance, malware development, and target prioritization, creating more sophisticated and stealthy malware.

Group-IB has identified a new Python-based Windows malware framework called BraZetsu, operated by a group tracked as Exilware. This framework functions as a commercial marketplace, known as 'Banco de Infects', allowing Initial Access Brokers to monetize compromised systems. This 'access-as-a-service' model enables criminals to purchase entry points into victim systems for approximately $5.80, facilitating the deployment of secondary payloads.

Simultaneously, ransomware operations are shifting toward a standardized, high-volume business model. According to Verizon, ransomware now accounts for 48% of all breaches. While the median ransom paid has decreased to $139,875, criminal groups are compensating for lower individual payouts by using repeatable 'playbooks' and exploiting known vulnerabilities at scale, similar to a generics pharmaceutical manufacturer.

Entities

Exilware · Group-IB · Verizon