Skip to content
Malware family

Brute Ratel C4

Brute Ratel C4, also referred to as BRC4 or Brute Ratel, is a commercial post-exploitation and command-and-control framework described as a customized attack simulation tool designed to evade common defensive controls, including detection of EDR userland hooks.

Profile source: Mallory opens in a new tab

Brute Ratel C4

Family profile

Brute Ratel C4, also referred to as BRC4 or Brute Ratel, is a commercial post-exploitation and command-and-control framework described as a customized attack simulation tool designed to evade common defensive controls, including detection of EDR userland hooks. Its implants can take multiple forms, including executables, service binaries, DLLs, and PowerShell scripts. Reported capabilities in the provided content include process creation and injection for defense evasion, privilege escalation, lateral movement via SMB and WMI, account and domain discovery using LDAP queries, net group "Domain Admins" /domain, and net user /domain, and network/service discovery including port scanning. The content also references HTTP fingerprinting research that identified Brute Ratel infrastructure, including a sample HTTP-Basma verbosus fingerprint beginning "01140a85e40014512f3612140a85e422140a85e422140a85e4220000140a85e4220000000001" and a sample pacto fingerprint of "0207292309a7a7e798e417d69df5f2a5".

The framework has been observed in multiple intrusion chains and campaigns. The content states that Brute Ratel C4 has gained execution through users opening malicious documents, and Proofpoint identified a 20 September 2024 ClickFix campaign using HTML attachments with filenames beginning with "Report_" or "scan_doc_" that copied base64-encoded PowerShell into the clipboard; if executed, the PowerShell downloaded a DLL that started Brute Ratel and was then observed leading to Latrodectus. QakBot/QBot infections were also described as leading to Cobalt Strike or Brute Ratel, and Red Canary reported that Latrodectus activity resumed by late June 2024 and was observed being dropped by Brute Ratel. In May 2024, Arechclient2 reportedly delivered Cobalt Strike and Brute Ratel as a precursor to BlackSuit ransomware deployment. CERT Polska and Poland’s Military Counterintelligence Service reported an espionage campaign linked to Russian intelligence services and overlapping with APT29/NOBELIUM tradecraft in which victims were lured via spear-phishing, compromised websites, ENVYSCOUT HTML smuggling, and ZIP/ISO/IMG files; if victims passed manual verification, operators delivered Cobalt Strike or Brute Ratel. Microsoft also observed DEV-0506 adding Brute Ratel in late September 2022 to facilitate hands-on-keyboard access alongside Cobalt Strike Beacons. The content further notes that APT29 has been cited as using Brute Ratel C4, and that many threat actors have shifted toward tools such as Brute Ratel as alternatives to heavily detected frameworks like Cobalt Strike.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 19, 2026
Last activity
Jul 19, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • DigitalOcean, LLC1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

29 named in public reporting
TA578

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

TA571

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

DEV-0506

In late September 2022, Microsoft observed DEV-0506 adding Brute Ratel as a tool to facilitate their hands-on-keyboard access as well as Cobalt Strike Beacons.

APT29

Currently, there are many APT groups and cybercrime gangs using this technique. Some examples include: APT41 Group, Aquatic Panda, APT29 using Brute Ratel C4...

Lunar Spider

Victims searching tax-related content are redirected to download malicious JavaScript files like Document-16-32-50.js. These scripts retrieve an MSI installer, which deploys Brute Ratel C4 (BRc4) by disguising the payload as legitimate software (vierm_soft_x64.dll under rundll32 execution).

APT41

Insikt Group observed a late 2022 RedHotel campaign which employed a stolen code signing certificate ... to load the offensive security tool (OST) Brute Ratel C4.

TeamTNT

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Poseidon Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

DarkVishnya

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Suckfly

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

APT32

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Storm-0501

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Medusa Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Sowbug

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

OilRig

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Axiom

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Tonto

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

FIN7

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

APT39

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

GOLD SOUTHFIELD

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Sandworm

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Ember Bear

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Cobalt Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Mustang Panda

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Carbanak

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Leviathan

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

MuddyWater

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Exploited software

Vulnerabilities linked to Brute Ratel C4

3 CVEs

MITRE ATT&CK

Brute Ratel C4 in ATT&CK

83 distinct techniques

Techniques

83 techniques
T1518.001 Security Software Discovery T1595 Active Scanning T1590 Gather Victim Network Information T1071 Application Layer Protocol T1580 Cloud Infrastructure Discovery T1021.002 SMB/Windows Admin Shares T1140 Deobfuscate/Decode Files or Information T1071.001 Web Protocols T1018 Remote System Discovery T1055 Process Injection T1069.002 Domain Groups T1087.002 Domain Account T1204.002 Malicious File T1204 User Execution T1566.001 Spearphishing Attachment T1566 Phishing T1105 Ingress Tool Transfer T1059.001 PowerShell T1027 Obfuscated Files or Information T1041 Exfiltration Over C2 Channel T1057 Process Discovery T1059.003 Windows Command Shell T1219 Remote Access Tools T1036 Masquerading T1036.005 Match Legitimate Resource Name or Location T1021.003 Distributed Component Object Model T1047 Windows Management Instrumentation T1562.001 Disable or Modify Tools T1046 Network Service Discovery T1570 Lateral Tool Transfer T1574.001 DLL T1190 Exploit Public-Facing Application T1562 Impair Defenses T1012 Query Registry T1083 File and Directory Discovery T1222 File and Directory Permissions Modification T1113 Screen Capture T1620 Reflective Code Loading T1134.004 Parent PID Spoofing T1132 Data Encoding T1033 System Owner/User Discovery T1082 System Information Discovery T1134.002 Create Process with Token T1134 Access Token Manipulation T1059 Command and Scripting Interpreter T1548 Abuse Elevation Control Mechanism T1115 Clipboard Data T1489 Service Stop T1070.004 File Deletion T1547.001 Registry Run Keys / Startup Folder T1583 Acquire Infrastructure T1070 Indicator Removal T1124 System Time Discovery T1007 System Service Discovery T1529 System Shutdown/Reboot T1490 Inhibit System Recovery T1608.006 SEO Poisoning T1021 Remote Services T1069 Permission Groups Discovery T1482 Domain Trust Discovery T1134.001 Token Impersonation/Theft T1059.007 JavaScript T1652 Device Driver Discovery T1497.001 System Checks T1218.011 Rundll32 T1027.007 Dynamic API Resolution T1564.010 Process Argument Spoofing T1087 Account Discovery T1056 Input Capture T1543 Create or Modify System Process T1055.004 Asynchronous Procedure Call T1048 Exfiltration Over Alternative Protocol T1059.005 Visual Basic T1106 Native API T1059.006 Python T1564.001 Hidden Files and Directories T1102 Web Service T1204.001 Malicious Link T1127.001 MSBuild T1003 OS Credential Dumping T1559 Inter-Process Communication T1555.003 Credentials from Web Browsers T1003.001 LSASS Memory

Reporting

Research mentioning Brute Ratel C4

Apr 3
Derp Ca

SERPENTINE#CLOUD returns: ClickFix lure drops five RATs | Derp

The payload set is familiar: VenomRAT, AsyncRAT, XWorm/Violet, PureHVNC, and a new addition -- Brute Ratel C4. BRc4 replaces the Annorii loader from the prior campaign. It does not operate its own C2. Instead, it decrypts and injects PureHVNC stage 2 into notepad.exe using Early Bird APC.

Mar 12
Breakglass Intel

Shadow RAT Panel v2.0: Inside a Live MaaS Platform With APT Crossover - Breakglass Intelligence - Breakglass Intelligence

This is not unprecedented -- tools like Cobalt Strike and Brute Ratel began as legitimate security tools before being adopted by threat actors...

Feb 25
Splunk Research

Detection: Windows Remote Access Software BRC4 Loaded Dll | Splunk Security Content

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Feb 25
Splunk Research

Detection: Windows Suspicious C2 Named Pipe | Splunk Security Content

Associated Analytic Story APT37 Rustonotto and FadeStealer, BlackByte Ransomware, Brute Ratel C4, Cobalt Strike, DarkSide Ransomware, Gozi Malware, Graceful Wipe Out Attack, Hellcat Ransomware, LockBit Ransomware, Meterpreter, Remote Monitoring and Management Software, Storm-0501 Ransomware, Trickbot, Tuoni

Feb 13
Cloudatg Insights

AI Development & Software Engineering | CloudATG

"...upload JSP web shells with the goal of facilitating unauthorized file uploads and code execution... Brute Ratel Framework"

Feb 9
Splunk Research

Detection: Windows Hijack Execution Flow Version Dll Side Load | Splunk Security Content

This activity is significant as it is a common technique used in ransomware and APT malware campaigns, including Brute Ratel C4, to execute malicious code via DLL side loading.

Feb 5
The Hacker News

ThreatsDay Bulletin: Codespaces RCE, AsyncRAT C2, BYOVD Abuse, AI Cloud Intrusions & 15+ Stories

ShadowSyndicate continues to be associated with toolkits including ... Brute Ratel.

Jan 1
Red Canary Threat Report

C2 Frameworks - Red Canary Threat Detection Report

Brute Ratel is a commercial post-exploitation framework with implants that can take many forms, including executables, service binaries, DLLs, and PowerShell scripts.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.