Last seven days
- First activity
- Sep 14, 2026
- Last activity
- Sep 17, 2026
- Feed role
- C2
- Host form
- 6 IP / 0 hostnames
Brute Ratel C4 is a commercial post-exploitation command-and-control framework created for red-team operations that has been repeatedly abused by threat actors, including ransomware operators and espionage-focused intruders.
Profile source: Mallory opens in a new tabBrute Ratel C4
Brute Ratel C4 is a commercial post-exploitation command-and-control framework created for red-team operations that has been repeatedly abused by threat actors, including ransomware operators and espionage-focused intruders. It is commonly used as an alternative to Cobalt Strike and deploys implants known as badgers that provide covert remote access to compromised systems. Observed malicious use includes execution of attacker commands, establishment of stealthy command-and-control channels, persistence, lateral movement, payload delivery, and support for follow-on ransomware activity. The framework has also been noted for defensive-evasion features such as detection of EDR userland hooks, and some intrusion chains have loaded it in memory or into legitimate processes to reduce visibility.
Brute Ratel C4 has appeared in multiple intrusion ecosystems rather than a single actor set. It has been observed in campaigns associated with Black Basta operations, in intrusions where QBot or Latrodectus delivered it as a follow-on payload, and in reporting linked to Nobelium and Patchwork-adjacent tradecraft discussions as part of broader attacker adoption of commercial or public offensive tooling. It has also been reported in activity thought to be connected to APT29-related operations, though attribution in some individual cases remains less certain than the malware identification itself.
Delivery and execution have varied by campaign. Document-themed phishing and spearphishing lures have been used to distribute archives or disk images that ultimately side-load Brute Ratel through benign applications. Observed chains include malicious ISO or IMG containers, Windows shortcut-based launchers, script-driven loaders, and DLL search order hijacking or side-loading using legitimate executables. Brute Ratel has also been deployed after exploitation of enterprise software vulnerabilities and by other malware families acting as loaders. In several cases, operators used private loaders or commodity malware to install Brute Ratel after initial access was established.
The framework primarily targets Windows environments in observed malicious use. Once active, it is used for post-compromise operations including persistence, remote command execution, lateral movement, and exfiltration support. Its role in real-world intrusions is best characterized as a stealth-oriented post-exploitation framework and backdoor capability that bridges initial access to hands-on-keyboard operations, credential and network abuse, and eventual monetization such as ransomware deployment.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Recently, our Unit 42 incident response team was engaged in a Black Basta breach response that uncovered several tools and malware samples on the victim's machines, including GootLoader malware, Brute Ratel C4 red-teaming tool and an older PlugX malware sample.
Threat actors spread malicious ISOs... The in-memory code, Brute Ratel C4, starts to communicate with IP 174.129.157[.]251 on TCP port 443... The threat actors can remotely access the infected device once the Brute Ratel has been loaded in order to run commands and spread farther throughout the compromised network.
References https://medium.com/@knownsec404team/the-patchwork-group-has-updated-its-arsenal-launching-attacks-for-the-first-time-using-brute-ratel-175741987d87
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
In late September 2022, Microsoft observed DEV-0506 adding Brute Ratel as a tool to facilitate their hands-on-keyboard access as well as Cobalt Strike Beacons.
Victims searching tax-related content are redirected to download malicious JavaScript files like Document-16-32-50.js. These scripts retrieve an MSI installer, which deploys Brute Ratel C4 (BRc4) by disguising the payload as legitimate software (vierm_soft_x64.dll under rundll32 execution).
Insikt Group observed a late 2022 RedHotel campaign which employed a stolen code signing certificate ... to load the offensive security tool (OST) Brute Ratel C4.
"...C2 frameworks like Brute Ratel c4 and Ragnar Loader."
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
ShadowSyndicate continues to be associated with toolkits including ... Brute Ratel.
Exploited software
MITRE ATT&CK
Reporting
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.
Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112. The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.
Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries. The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.