Last seven days
- First activity
- Jul 19, 2026
- Last activity
- Jul 19, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
Brute Ratel C4, also referred to as BRC4 or Brute Ratel, is a commercial post-exploitation and command-and-control framework described as a customized attack simulation tool designed to evade common defensive controls, including detection of EDR userland hooks.
Profile source: Mallory opens in a new tabBrute Ratel C4
Brute Ratel C4, also referred to as BRC4 or Brute Ratel, is a commercial post-exploitation and command-and-control framework described as a customized attack simulation tool designed to evade common defensive controls, including detection of EDR userland hooks. Its implants can take multiple forms, including executables, service binaries, DLLs, and PowerShell scripts. Reported capabilities in the provided content include process creation and injection for defense evasion, privilege escalation, lateral movement via SMB and WMI, account and domain discovery using LDAP queries, net group "Domain Admins" /domain, and net user /domain, and network/service discovery including port scanning. The content also references HTTP fingerprinting research that identified Brute Ratel infrastructure, including a sample HTTP-Basma verbosus fingerprint beginning "01140a85e40014512f3612140a85e422140a85e422140a85e4220000140a85e4220000000001" and a sample pacto fingerprint of "0207292309a7a7e798e417d69df5f2a5".
The framework has been observed in multiple intrusion chains and campaigns. The content states that Brute Ratel C4 has gained execution through users opening malicious documents, and Proofpoint identified a 20 September 2024 ClickFix campaign using HTML attachments with filenames beginning with "Report_" or "scan_doc_" that copied base64-encoded PowerShell into the clipboard; if executed, the PowerShell downloaded a DLL that started Brute Ratel and was then observed leading to Latrodectus. QakBot/QBot infections were also described as leading to Cobalt Strike or Brute Ratel, and Red Canary reported that Latrodectus activity resumed by late June 2024 and was observed being dropped by Brute Ratel. In May 2024, Arechclient2 reportedly delivered Cobalt Strike and Brute Ratel as a precursor to BlackSuit ransomware deployment. CERT Polska and Polandβs Military Counterintelligence Service reported an espionage campaign linked to Russian intelligence services and overlapping with APT29/NOBELIUM tradecraft in which victims were lured via spear-phishing, compromised websites, ENVYSCOUT HTML smuggling, and ZIP/ISO/IMG files; if victims passed manual verification, operators delivered Cobalt Strike or Brute Ratel. Microsoft also observed DEV-0506 adding Brute Ratel in late September 2022 to facilitate hands-on-keyboard access alongside Cobalt Strike Beacons. The content further notes that APT29 has been cited as using Brute Ratel C4, and that many threat actors have shifted toward tools such as Brute Ratel as alternatives to heavily detected frameworks like Cobalt Strike.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
In late September 2022, Microsoft observed DEV-0506 adding Brute Ratel as a tool to facilitate their hands-on-keyboard access as well as Cobalt Strike Beacons.
Currently, there are many APT groups and cybercrime gangs using this technique. Some examples include: APT41 Group, Aquatic Panda, APT29 using Brute Ratel C4...
Victims searching tax-related content are redirected to download malicious JavaScript files like Document-16-32-50.js. These scripts retrieve an MSI installer, which deploys Brute Ratel C4 (BRc4) by disguising the payload as legitimate software (vierm_soft_x64.dll under rundll32 execution).
Insikt Group observed a late 2022 RedHotel campaign which employed a stolen code signing certificate ... to load the offensive security tool (OST) Brute Ratel C4.
"...C2 frameworks like Brute Ratel c4 and Ragnar Loader."
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
ShadowSyndicate continues to be associated with toolkits including ... Brute Ratel.
Exploited software
MITRE ATT&CK
Reporting
The payload set is familiar: VenomRAT, AsyncRAT, XWorm/Violet, PureHVNC, and a new addition -- Brute Ratel C4. BRc4 replaces the Annorii loader from the prior campaign. It does not operate its own C2. Instead, it decrypts and injects PureHVNC stage 2 into notepad.exe using Early Bird APC.
This is not unprecedented -- tools like Cobalt Strike and Brute Ratel began as legitimate security tools before being adopted by threat actors...
This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.
Associated Analytic Story APT37 Rustonotto and FadeStealer, BlackByte Ransomware, Brute Ratel C4, Cobalt Strike, DarkSide Ransomware, Gozi Malware, Graceful Wipe Out Attack, Hellcat Ransomware, LockBit Ransomware, Meterpreter, Remote Monitoring and Management Software, Storm-0501 Ransomware, Trickbot, Tuoni
"...upload JSP web shells with the goal of facilitating unauthorized file uploads and code execution... Brute Ratel Framework"
This activity is significant as it is a common technique used in ransomware and APT malware campaigns, including Brute Ratel C4, to execute malicious code via DLL side loading.
ShadowSyndicate continues to be associated with toolkits including ... Brute Ratel.
Brute Ratel is a commercial post-exploitation framework with implants that can take many forms, including executables, service binaries, DLLs, and PowerShell scripts.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.