Skip to content

Brute Ratel C4

Also known as: BOLDBADGER, BruteRatel

Brute Ratel C4 (BRC4) is a commercial framework for red-teaming and adversarial attack simulation, which made its first appearance in December 2020. It was specifically designed to evade detection by endpoint detection and response (EDR) and antivirus (AV) capabilities. BRC4 allows operators to deploy a backdoor agent known as Badger (aka BOLDBADGER) within a target environment.

This agent enables arbitrary command execution, facilitating lateral movement, privilege escalation, and the establishment of additional persistence avenues. The Badger backdoor agent can communicate with a remote server via DNS over HTTPS, HTTP, HTTPS, SMB, and TCP, using custom encrypted channels. It supports a variety of backdoor commands including shell command execution, file transfers, file execution, and credential harvesting. Additionally, the Badger agent can perform tasks such as port scanning, screenshot capturing, and keystroke logging. Notably, in September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.

C2 Infrastructure

ISP/Residential 100%

Last 7 days

Jun 16, 2026
C2 Hosts: 1

Further Reading

0xdarkvortex.dev opens in a new tab
0xdarkvortex.dev
0xdarkvortex.dev opens in a new tab
0xdarkvortex.dev
andreafortuna.org opens in a new tab
andreafortuna.org
blog.eclecticiq.com opens in a new tab
blog.eclecticiq.com
blog.krakz.fr opens in a new tab
blog.krakz.fr
blog.reveng.ai opens in a new tab
blog.reveng.ai
blog.spookysec.net opens in a new tab
blog.spookysec.net
bruteratel.com opens in a new tab
bruteratel.com
cybergeeks.tech opens in a new tab
cybergeeks.tech
cybergeeks.tech opens in a new tab
cybergeeks.tech
go.recordedfuture.com opens in a new tab
go.recordedfuture.com
info.spamhaus.com opens in a new tab
info.spamhaus.com
insights.bridewell.com opens in a new tab
insights.bridewell.com
medium.com opens in a new tab
medium.com
michaelkoczwara.medium.com opens in a new tab
michaelkoczwara.medium.com
protectedmo.de opens in a new tab
protectedmo.de
query.prod.cms.rt.microsoft.com opens in a new tab
query.prod.cms.rt.microsoft.com
socradar.io opens in a new tab
socradar.io
thedfirreport.com opens in a new tab
thedfirreport.com
twitter.com opens in a new tab
twitter.com
twitter.com opens in a new tab
twitter.com
unit42.paloaltonetworks.com opens in a new tab
unit42.paloaltonetworks.com
web.archive.org opens in a new tab
web.archive.org
mandiant.com opens in a new tab
mandiant.com
mdsec.co.uk opens in a new tab
mdsec.co.uk
microsoft.com opens in a new tab
microsoft.com
proofpoint.com opens in a new tab
proofpoint.com
protect.airbus.com opens in a new tab
protect.airbus.com
splunk.com opens in a new tab
splunk.com
trendmicro.com opens in a new tab
trendmicro.com
youtube.com opens in a new tab
youtube.com