Last seven days
- First activity
- Aug 2, 2026
- Last activity
- Aug 2, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
Brute Ratel C4, also known as BRC4, is a commercial post-exploitation command-and-control framework used to establish and maintain access on compromised Windows systems.
Profile source: Mallory opens in a new tabBrute Ratel C4
Brute Ratel C4, also known as BRC4, is a commercial post-exploitation command-and-control framework used to establish and maintain access on compromised Windows systems. It is designed as an adversary simulation and offensive security platform, but has been adopted in real intrusions by both financially motivated and state-linked threat actors as an alternative to more heavily detected frameworks such as Cobalt Strike. Observed use includes hands-on-keyboard intrusions, follow-on activity after loader infections, and deployment during broader ransomware and espionage operations.
Brute Ratel implants can be delivered and executed in multiple forms, including executables, service binaries, DLLs, and PowerShell scripts. Reported intrusion chains show it arriving as a follow-on payload from malware such as QakBot, Latrodectus, and Arechclient2, and it has also been observed after exploitation of internet-facing enterprise software vulnerabilities. User-driven execution has been documented through malicious documents and HTML attachment campaigns that trick victims into launching attacker-supplied PowerShell, including ClickFix-style lures.
The framework emphasizes defense evasion and post-compromise flexibility. Documented capabilities include detection of EDR userland hooks, process creation and process injection, privilege escalation, persistence, lateral movement via WMI and SMB, account and domain discovery using LDAP and native Windows commands, and port scanning against target systems. It is used to support deeper compromise after initial access, including operator-controlled reconnaissance and movement across Active Directory environments.
Brute Ratel C4 has been associated with multiple intrusion sets and campaigns. Microsoft reported DEV-0506 using it alongside Cobalt Strike for interactive access. It has been observed in campaigns linked to QakBot activity, in intrusions preceding BlackSuit ransomware deployment, and in espionage operations targeting diplomatic and government-related entities where victims were manually vetted before operators deployed Brute Ratel or Cobalt Strike. It has also been seen in activity exploiting SAP NetWeaver vulnerability CVE-2025-31324 to maintain persistent access on compromised servers.
The framework primarily targets Windows environments and is best understood as dual-use offensive tooling whose malicious significance depends on deployment context. In the wild, its presence commonly indicates an active post-exploitation phase and a likely broader intrusion rather than a standalone commodity infection.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
In late September 2022, Microsoft observed DEV-0506 adding Brute Ratel as a tool to facilitate their hands-on-keyboard access as well as Cobalt Strike Beacons.
Currently, there are many APT groups and cybercrime gangs using this technique. Some examples include: APT41 Group, Aquatic Panda, APT29 using Brute Ratel C4...
Victims searching tax-related content are redirected to download malicious JavaScript files like Document-16-32-50.js. These scripts retrieve an MSI installer, which deploys Brute Ratel C4 (BRc4) by disguising the payload as legitimate software (vierm_soft_x64.dll under rundll32 execution).
Insikt Group observed a late 2022 RedHotel campaign which employed a stolen code signing certificate ... to load the offensive security tool (OST) Brute Ratel C4.
"...C2 frameworks like Brute Ratel c4 and Ragnar Loader."
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
ShadowSyndicate continues to be associated with toolkits including ... Brute Ratel.
Exploited software
MITRE ATT&CK
Reporting
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.