Skip to content

Brute Ratel C4

Brute Ratel C4 is a commercial post-exploitation command-and-control framework created for red-team operations that has been repeatedly abused by threat actors, including ransomware operators and espionage-focused intruders.

Profile source: Mallory opens in a new tab

Brute Ratel C4

Family profile

Brute Ratel C4 is a commercial post-exploitation command-and-control framework created for red-team operations that has been repeatedly abused by threat actors, including ransomware operators and espionage-focused intruders. It is commonly used as an alternative to Cobalt Strike and deploys implants known as badgers that provide covert remote access to compromised systems. Observed malicious use includes execution of attacker commands, establishment of stealthy command-and-control channels, persistence, lateral movement, payload delivery, and support for follow-on ransomware activity. The framework has also been noted for defensive-evasion features such as detection of EDR userland hooks, and some intrusion chains have loaded it in memory or into legitimate processes to reduce visibility.

Brute Ratel C4 has appeared in multiple intrusion ecosystems rather than a single actor set. It has been observed in campaigns associated with Black Basta operations, in intrusions where QBot or Latrodectus delivered it as a follow-on payload, and in reporting linked to Nobelium and Patchwork-adjacent tradecraft discussions as part of broader attacker adoption of commercial or public offensive tooling. It has also been reported in activity thought to be connected to APT29-related operations, though attribution in some individual cases remains less certain than the malware identification itself.

Delivery and execution have varied by campaign. Document-themed phishing and spearphishing lures have been used to distribute archives or disk images that ultimately side-load Brute Ratel through benign applications. Observed chains include malicious ISO or IMG containers, Windows shortcut-based launchers, script-driven loaders, and DLL search order hijacking or side-loading using legitimate executables. Brute Ratel has also been deployed after exploitation of enterprise software vulnerabilities and by other malware families acting as loaders. In several cases, operators used private loaders or commodity malware to install Brute Ratel after initial access was established.

The framework primarily targets Windows environments in observed malicious use. Once active, it is used for post-compromise operations including persistence, remote command execution, lateral movement, and exfiltration support. Its role in real-world intrusions is best characterized as a stealth-oriented post-exploitation framework and backdoor capability that bridges initial access to hands-on-keyboard operations, credential and network abuse, and eventual monetization such as ransomware deployment.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 14, 2026
Last activity
Sep 17, 2026
Feed role
C2
Host form
6 IP / 0 hostnames

Leading locations

  • IT2
  • JP2
  • CH1
  • MD1

Leading providers

  • Amazon.com, Inc.2
  • COLT Technology Services Group Limited1
  • Fastweb SpA1
  • MivoCloud SRL1
  • Private Layer INC1

Infrastructure traits

  • Hosting 4

Samples

Recent associated samples

Reported operators

Threat actors

31 named in public reporting
Black Basta

Recently, our Unit 42 incident response team was engaged in a Black Basta breach response that uncovered several tools and malware samples on the victim's machines, including GootLoader malware, Brute Ratel C4 red-teaming tool and an older PlugX malware sample.

APT29

Threat actors spread malicious ISOs... The in-memory code, Brute Ratel C4, starts to communicate with IP 174.129.157[.]251 on TCP port 443... The threat actors can remotely access the infected device once the Brute Ratel has been loaded in order to run commands and spread farther throughout the compromised network.

Patchwork

References https://medium.com/@knownsec404team/the-patchwork-group-has-updated-its-arsenal-launching-attacks-for-the-first-time-using-brute-ratel-175741987d87

TA578

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

TA571

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

DEV-0506

In late September 2022, Microsoft observed DEV-0506 adding Brute Ratel as a tool to facilitate their hands-on-keyboard access as well as Cobalt Strike Beacons.

Lunar Spider

Victims searching tax-related content are redirected to download malicious JavaScript files like Document-16-32-50.js. These scripts retrieve an MSI installer, which deploys Brute Ratel C4 (BRc4) by disguising the payload as legitimate software (vierm_soft_x64.dll under rundll32 execution).

Earth Lusca

Insikt Group observed a late 2022 RedHotel campaign which employed a stolen code signing certificate ... to load the offensive security tool (OST) Brute Ratel C4.

TeamTNT

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Poseidon Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

DarkVishnya

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Suckfly

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

APT32

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Storm-0501

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Medusa Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Sowbug

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

OilRig

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Axiom

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Tonto

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

FIN7

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

APT39

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

GOLD SOUTHFIELD

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Sandworm

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Ember Bear

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Cobalt Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Mustang Panda

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Carbanak

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Leviathan

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

MuddyWater

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including ... Brute Ratel.

Exploited software

Vulnerabilities linked to Brute Ratel C4

3 CVEs

MITRE ATT&CK

Brute Ratel C4 in ATT&CK

93 distinct techniques

Techniques

93 techniques
T1055 Process Injection T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1518.001 Security Software Discovery T1574.001 DLL T1134 Access Token Manipulation T1012 Query Registry T1082 System Information Discovery T1115 Clipboard Data T1204 User Execution T1518 Software Discovery T1622 Debugger Evasion T1113 Screen Capture T1003 OS Credential Dumping T1070 Indicator Removal T1057 Process Discovery T1620 Reflective Code Loading T1560 Archive Collected Data T1566.001 Spearphishing Attachment T1033 System Owner/User Discovery T1482 Domain Trust Discovery T1007 System Service Discovery T1055.004 Asynchronous Procedure Call T1134.004 Parent PID Spoofing T1055.003 Thread Execution Hijacking T1106 Native API T1059 Command and Scripting Interpreter T1219 Remote Access Tools T1016 System Network Configuration Discovery T1001 Data Obfuscation T1562 Impair Defenses T1059.003 Windows Command Shell T1204.002 Malicious File T1140 Deobfuscate/Decode Files or Information T1083 File and Directory Discovery T1134.001 Token Impersonation/Theft T1566 Phishing T1027 Obfuscated Files or Information T1027.007 Dynamic API Resolution T1027.002 Software Packing T1497 Virtualization/Sandbox Evasion T1573 Encrypted Channel T1572 Protocol Tunneling T1570 Lateral Tool Transfer T1102 Web Service T1543 Create or Modify System Process T1190 Exploit Public-Facing Application T1595 Active Scanning T1590 Gather Victim Network Information T1580 Cloud Infrastructure Discovery T1021.002 SMB/Windows Admin Shares T1071.001 Web Protocols T1018 Remote System Discovery T1069.002 Domain Groups T1087.002 Domain Account T1059.001 PowerShell T1041 Exfiltration Over C2 Channel T1036 Masquerading T1036.005 Match Legitimate Resource Name or Location T1021.003 Distributed Component Object Model T1047 Windows Management Instrumentation T1562.001 Disable or Modify Tools T1046 Network Service Discovery T1222 File and Directory Permissions Modification T1132 Data Encoding T1134.002 Create Process with Token T1548 Abuse Elevation Control Mechanism T1489 Service Stop T1070.004 File Deletion T1547.001 Registry Run Keys / Startup Folder T1583 Acquire Infrastructure T1124 System Time Discovery T1529 System Shutdown/Reboot T1490 Inhibit System Recovery T1608.006 SEO Poisoning T1021 Remote Services T1069 Permission Groups Discovery T1059.007 JavaScript T1652 Device Driver Discovery T1497.001 System Checks T1218.011 Rundll32 T1564.010 Process Argument Spoofing T1087 Account Discovery T1056 Input Capture T1048 Exfiltration Over Alternative Protocol T1059.005 Visual Basic T1059.006 Python T1564.001 Hidden Files and Directories T1204.001 Malicious Link T1127.001 MSBuild T1559 Inter-Process Communication T1555.003 Credentials from Web Browsers T1003.001 LSASS Memory

Reporting

Research mentioning Brute Ratel C4

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jan 1
Sophos Threat Research

A new APT uses DLL side-loads to “KilllSomeOne” | SOPHOS

Sophos has identified a new PlugX USB worm variant spreading through removable media in outbreaks across Papua New Guinea, Ghana, Mongolia, Zimbabwe, and Nigeria, using DLL sideloading with legitimate AvastSvc.exe, a malicious wsc.dll, and an encrypted PlugX payload. The malware hides files on infected USB drives, gathers host reconnaissance, and steals Office and PDF documents up to 300 MB, storing them in encrypted form under RECYCLER.BIN with base64-obfuscated filenames before attempting exfiltration to infrastructure including 45.142.166[.]112. The activity aligns with the long-running PKPLUG espionage cluster, which researchers have previously attributed with high confidence to a Chinese nation-state adversary targeting victims in and around Southeast Asia, including Xinjiang, Mongolia, Myanmar, and Taiwan. Earlier reporting tied PKPLUG to malware families including PlugX, Poison Ivy, 9002, Zupdax, Farseer, and the Android spyware HenBox, and documented overlapping infrastructure, DLL sideloading, registry-based persistence, and surveillance-focused collection against regional targets, reinforcing the assessment that the new worm is part of a broader intelligence-gathering campaign.

Jan 1
Sophos Threat Research

A border-hopping PlugX USB worm takes its act on the road | SOPHOS

Jan 26
Palo Alto Networks Unit 42

Chinese PlugX Malware Hidden in Your USB Devices?

Nov 2
Cyble Blog Historic

Cyble - New Laplas Clipper Distributed Via SmokeLoader

Researchers reported multiple financially motivated malware campaigns using SmokeLoader as a delivery mechanism for follow-on payloads including Gozi ISFB, ZLoader, Oski, AveMaria, Cobalt Strike, SystemBC, RecordBreaker, and the Laplas Clipper cryptocurrency hijacker. In one campaign set, attackers abused website contact forms and sent phishing lures posing as copyright complaints, directing victims to malicious documents hosted on legitimate services such as Google Drive. Talos found the initial payloads were wrapped in a shared crypter identified by the DOS-stub string "Salfram," indicating a common tooling layer across otherwise varied malware deliveries. The activity relied on evasive and modular infection chains designed to complicate detection and maximize monetization. The Salfram crypter used obfuscation methods including fake API calls, fragmented control flow, self-modifying code, and memory allocation through ZwAllocateVirtualMemory, while later-stage malware added persistence and theft capabilities. Cyble said Laplas Clipper monitored the clipboard for cryptocurrency wallet addresses, pulled regex patterns and replacement addresses from clipper[.]guru, and persisted by copying itself into %appdata% and creating a scheduled task that ran every minute. The combined use of phishing, legitimate hosting platforms, crypter-based obfuscation, and multi-payload delivery shows an adaptable criminal ecosystem built to steal credentials, proxy access, banking data, and cryptocurrency funds.

Oct 12
Trendmicro

Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike

Sep 3
Talosintelligence Other

Salfram: Robbing the place without removing your name tag

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.