Brute Ratel C4
MITRE ATT&CK: S1063 View on attack.mitre.org
Aliases: BRc4, BOLDBADGER, BruteRatel, Brute Ratel C4
- First seen
- 2020-12-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 331 (58 malicious)
- Last IoC activity
- 2026-09-02 00:36:29
- Profile updated
- 2026-07-07 13:02:12
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications healthcare-and-pharmaceutical professional-services
Context
Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.
Recent IoC activity
58 malicious indicators in Maltiverse are attributed to Brute Ratel C4 (S1063). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | deltaso.com | 2026-09-03 | 1 |
| hostname | br.libjs.xyz | 2026-09-02 | 1 |
| hostname | cdn.belladonnarestaurant.co.uk | 2026-09-02 | 1 |
| hostname | systemresync.com | 2026-09-02 | 1 |
| file sample | aprun.exe | 2026-09-01 | 4 |
| hostname | adevsoftinc.com | 2026-08-27 | 1 |
| IP address | 13.231.27.0 | 2026-08-26 | 1 |
| hostname | ekcdn.top | 2026-08-25 | 1 |
| IP address | 35.73.165.146 | 2026-08-22 | 1 |
| file sample | 62cb24967c6ce18d35d2a23ebed4217889d796cf7799d9075c1aa7752b8d3967 | 2026-08-21 | 2 |
| IP address | 57.181.120.61 | 2026-08-11 | 1 |
| URL | https://obobobo.com:8042/boku.php | 2026-08-10 | 1 |
| URL | https://sosachwaffen.com:8042/goku.php | 2026-08-10 | 1 |
| URL | https://pobegskichi.com:8042/boku.php | 2026-08-10 | 1 |
| IP address | 57.182.128.31 | 2026-08-08 | 1 |
| IP address | 37.117.191.175 | 2026-08-04 | 2 |
| hostname | 08us4w0132ps.shop | 2026-08-02 | 1 |
| URL | https://greshunka.com:8041/admin.php | 2026-07-18 | 1 |
| file sample | 7d30c01dcb8bb19069f96f84ee4b693f4540783f5ccae37eeb1cd3d3f71bc939.bin | 2026-07-14 | 3 |
| hostname | syncme.life | 2026-07-10 | 1 |
Detection coverage
- 7 YARA rules
- 829 Sigma rules
Malware & tools used
- Portable Executable Injection (attack-pattern)
- Service Execution (attack-pattern)
- Windows Command Shell (attack-pattern)
- Windows Remote Management (attack-pattern)
- Screen Capture (attack-pattern)
- Process Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Data from Local System (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Domain Groups (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Security Software Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Masquerade File Type (attack-pattern)
- Domain Account (attack-pattern)
- Remote Services (attack-pattern)
- Reflective Code Loading (attack-pattern)
- Network Service Discovery (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Native API (attack-pattern)
- Web Service (attack-pattern)
- DNS (attack-pattern)
Detection rules
- SIGNATURE_BASE_Brc4_Shellcode (yara-rule)
- SIGNATURE_BASE_HKTL_Bruteratel_Badger_Indicators_Oct22_4 (yara-rule)
- CAPE_Bruteratelsyscall (yara-rule)
- CAPE_Bruteratelpacker (yara-rule)
- CAPE_Bruterateldate (yara-rule)
- CAPE_Bruteratelconfig (yara-rule)
- CAPE_Bruteratel (yara-rule)
Reports & references
- go.recordedfuture.com — Cta 2023 0808 (report)
- Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
- Microsoft — Re54L7V (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- bruteratel.com (report)
- proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
- insights.bridewell.com — Cyber%20Threat%20Intelligence%20Report%202025 (report)
- Trend Micro — Black Basta Infiltrates Networks Via Qakbot Brute Ratel And Coba (report)
- blog.eclecticiq.com — Inside Intelligence Center Lunar Spider Enabling Ransomware Attacks On Financial Sector With Brute Ratel C4 And Latrodectus (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Brute Ratel C4 (report)
- blog.spookysec.net — Analyzing Brc4 Badgers (report)
- michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
- 0xdarkvortex.dev — Hiding In Plainsight (report)
- blog.krakz.fr — Latrodectus (report)
- bruteratel.com — Pe Reflection Long Live The King (report)
- socradar.io — Brute Ratel Utilized By Threat Actors In New Ransomware Operations (report)
- cybergeeks.tech — A Deep Dive Into Brute Ratel C4 Payloads (report)
- twitter.com — 1652067563545800705 (report)
- blog.reveng.ai — Latrodectus Distribution Via Brc4 (report)
- splunk.com — Deliver A Strike By Reversing A Badger Brute Ratel Detection And Analysis (report)
- twitter.com — 1580030303950995456 (report)
- protectedmo.de — Brute (report)
- protect.airbus.com — Incident Response Analysis Of Recent Version Of Brc4 (report)
- medium.com — Brute Ratel Config Decoding Update 7820455022Cb (report)
- web.archive.org — Hunting Cyber Evil Ratels From The Targeted Attacks To The Widespread Usage Of Brute Ratel (report)
External references
- mitre-attack — S1063
- BRc4
- MDSec Brute Ratel August 2022
- Dark Vortex Brute Ratel C4
- Palo Alto Brute Ratel July 2022
- Trend Micro Black Basta October 2022
- SANS Brute Ratel October 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy