Skip to content

Brute Ratel C4

Brute Ratel C4, also known as BRC4, is a commercial post-exploitation command-and-control framework used to establish and maintain access on compromised Windows systems.

Profile source: Mallory opens in a new tab

Brute Ratel C4

Family profile

Brute Ratel C4, also known as BRC4, is a commercial post-exploitation command-and-control framework used to establish and maintain access on compromised Windows systems. It is designed as an adversary simulation and offensive security platform, but has been adopted in real intrusions by both financially motivated and state-linked threat actors as an alternative to more heavily detected frameworks such as Cobalt Strike. Observed use includes hands-on-keyboard intrusions, follow-on activity after loader infections, and deployment during broader ransomware and espionage operations.

Brute Ratel implants can be delivered and executed in multiple forms, including executables, service binaries, DLLs, and PowerShell scripts. Reported intrusion chains show it arriving as a follow-on payload from malware such as QakBot, Latrodectus, and Arechclient2, and it has also been observed after exploitation of internet-facing enterprise software vulnerabilities. User-driven execution has been documented through malicious documents and HTML attachment campaigns that trick victims into launching attacker-supplied PowerShell, including ClickFix-style lures.

The framework emphasizes defense evasion and post-compromise flexibility. Documented capabilities include detection of EDR userland hooks, process creation and process injection, privilege escalation, persistence, lateral movement via WMI and SMB, account and domain discovery using LDAP and native Windows commands, and port scanning against target systems. It is used to support deeper compromise after initial access, including operator-controlled reconnaissance and movement across Active Directory environments.

Brute Ratel C4 has been associated with multiple intrusion sets and campaigns. Microsoft reported DEV-0506 using it alongside Cobalt Strike for interactive access. It has been observed in campaigns linked to QakBot activity, in intrusions preceding BlackSuit ransomware deployment, and in espionage operations targeting diplomatic and government-related entities where victims were manually vetted before operators deployed Brute Ratel or Cobalt Strike. It has also been seen in activity exploiting SAP NetWeaver vulnerability CVE-2025-31324 to maintain persistent access on compromised servers.

The framework primarily targets Windows environments and is best understood as dual-use offensive tooling whose malicious significance depends on deployment context. In the wild, its presence commonly indicates an active post-exploitation phase and a likely broader intrusion rather than a standalone commodity infection.

Capabilities

  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 2, 2026
Last activity
Aug 2, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • JP2

Leading providers

  • Amazon.com, Inc.2

Infrastructure traits

  • Hosting 2

Reported operators

Threat actors

29 named in public reporting
TA578

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

TA571

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

DEV-0506

In late September 2022, Microsoft observed DEV-0506 adding Brute Ratel as a tool to facilitate their hands-on-keyboard access as well as Cobalt Strike Beacons.

APT29

Currently, there are many APT groups and cybercrime gangs using this technique. Some examples include: APT41 Group, Aquatic Panda, APT29 using Brute Ratel C4...

Lunar Spider

Victims searching tax-related content are redirected to download malicious JavaScript files like Document-16-32-50.js. These scripts retrieve an MSI installer, which deploys Brute Ratel C4 (BRc4) by disguising the payload as legitimate software (vierm_soft_x64.dll under rundll32 execution).

APT41

Insikt Group observed a late 2022 RedHotel campaign which employed a stolen code signing certificate ... to load the offensive security tool (OST) Brute Ratel C4.

TeamTNT

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Poseidon Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

DarkVishnya

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Suckfly

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

APT32

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Storm-0501

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Medusa Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Sowbug

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

OilRig

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Axiom

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Tonto

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

FIN7

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

APT39

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

GOLD SOUTHFIELD

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Sandworm

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Ember Bear

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Cobalt Group

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Mustang Panda

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Carbanak

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

Leviathan

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

MuddyWater

This activity is significant as it may indicate the presence of Brute Ratel C4, a sophisticated remote access tool used for credential dumping and other malicious activities.

ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including ... Brute Ratel.

Exploited software

Vulnerabilities linked to Brute Ratel C4

3 CVEs

MITRE ATT&CK

Brute Ratel C4 in ATT&CK

83 distinct techniques

Techniques

83 techniques
T1105 Ingress Tool Transfer T1190 Exploit Public-Facing Application T1518.001 Security Software Discovery T1595 Active Scanning T1590 Gather Victim Network Information T1071 Application Layer Protocol T1580 Cloud Infrastructure Discovery T1021.002 SMB/Windows Admin Shares T1140 Deobfuscate/Decode Files or Information T1071.001 Web Protocols T1018 Remote System Discovery T1055 Process Injection T1069.002 Domain Groups T1087.002 Domain Account T1204.002 Malicious File T1204 User Execution T1566.001 Spearphishing Attachment T1566 Phishing T1059.001 PowerShell T1027 Obfuscated Files or Information T1041 Exfiltration Over C2 Channel T1057 Process Discovery T1059.003 Windows Command Shell T1219 Remote Access Tools T1036 Masquerading T1036.005 Match Legitimate Resource Name or Location T1021.003 Distributed Component Object Model T1047 Windows Management Instrumentation T1562.001 Disable or Modify Tools T1046 Network Service Discovery T1570 Lateral Tool Transfer T1574.001 DLL T1562 Impair Defenses T1012 Query Registry T1083 File and Directory Discovery T1222 File and Directory Permissions Modification T1113 Screen Capture T1620 Reflective Code Loading T1134.004 Parent PID Spoofing T1132 Data Encoding T1033 System Owner/User Discovery T1082 System Information Discovery T1134.002 Create Process with Token T1134 Access Token Manipulation T1059 Command and Scripting Interpreter T1548 Abuse Elevation Control Mechanism T1115 Clipboard Data T1489 Service Stop T1070.004 File Deletion T1547.001 Registry Run Keys / Startup Folder T1583 Acquire Infrastructure T1070 Indicator Removal T1124 System Time Discovery T1007 System Service Discovery T1529 System Shutdown/Reboot T1490 Inhibit System Recovery T1608.006 SEO Poisoning T1021 Remote Services T1069 Permission Groups Discovery T1482 Domain Trust Discovery T1134.001 Token Impersonation/Theft T1059.007 JavaScript T1652 Device Driver Discovery T1497.001 System Checks T1218.011 Rundll32 T1027.007 Dynamic API Resolution T1564.010 Process Argument Spoofing T1087 Account Discovery T1056 Input Capture T1543 Create or Modify System Process T1055.004 Asynchronous Procedure Call T1048 Exfiltration Over Alternative Protocol T1059.005 Visual Basic T1106 Native API T1059.006 Python T1564.001 Hidden Files and Directories T1102 Web Service T1204.001 Malicious Link T1127.001 MSBuild T1003 OS Credential Dumping T1559 Inter-Process Communication T1555.003 Credentials from Web Browsers T1003.001 LSASS Memory

Reporting

Research mentioning Brute Ratel C4

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.