Brute Ratel C4

MITRE ATT&CK: S1063 View on attack.mitre.org

Aliases: BRc4, BOLDBADGER, BruteRatel, Brute Ratel C4

First seen
2020-12-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
331 (58 malicious)
Last IoC activity
2026-09-02 00:36:29
Profile updated
2026-07-07 13:02:12

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications healthcare-and-pharmaceutical professional-services

Context

Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.

Recent IoC activity

58 malicious indicators in Maltiverse are attributed to Brute Ratel C4 (S1063). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname deltaso.com 2026-09-03 1
hostname br.libjs.xyz 2026-09-02 1
hostname cdn.belladonnarestaurant.co.uk 2026-09-02 1
hostname systemresync.com 2026-09-02 1
file sample aprun.exe 2026-09-01 4
hostname adevsoftinc.com 2026-08-27 1
IP address 13.231.27.0 2026-08-26 1
hostname ekcdn.top 2026-08-25 1
IP address 35.73.165.146 2026-08-22 1
file sample 62cb24967c6ce18d35d2a23ebed4217889d796cf7799d9075c1aa7752b8d3967 2026-08-21 2
IP address 57.181.120.61 2026-08-11 1
URL https://obobobo.com:8042/boku.php 2026-08-10 1
URL https://sosachwaffen.com:8042/goku.php 2026-08-10 1
URL https://pobegskichi.com:8042/boku.php 2026-08-10 1
IP address 57.182.128.31 2026-08-08 1
IP address 37.117.191.175 2026-08-04 2
hostname 08us4w0132ps.shop 2026-08-02 1
URL https://greshunka.com:8041/admin.php 2026-07-18 1
file sample 7d30c01dcb8bb19069f96f84ee4b693f4540783f5ccae37eeb1cd3d3f71bc939.bin 2026-07-14 3
hostname syncme.life 2026-07-10 1

Detection coverage

  • 7 YARA rules
  • 829 Sigma rules

Malware & tools used

  • Portable Executable Injection (attack-pattern)
  • Service Execution (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Windows Remote Management (attack-pattern)
  • Screen Capture (attack-pattern)
  • Process Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Data from Local System (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Domain Groups (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • Domain Account (attack-pattern)
  • Remote Services (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Web Service (attack-pattern)
  • DNS (attack-pattern)

Detection rules

  • SIGNATURE_BASE_Brc4_Shellcode (yara-rule)
  • SIGNATURE_BASE_HKTL_Bruteratel_Badger_Indicators_Oct22_4 (yara-rule)
  • CAPE_Bruteratelsyscall (yara-rule)
  • CAPE_Bruteratelpacker (yara-rule)
  • CAPE_Bruterateldate (yara-rule)
  • CAPE_Bruteratelconfig (yara-rule)
  • CAPE_Bruteratel (yara-rule)

Reports & references

  • go.recordedfuture.com — Cta 2023 0808 (report)
  • Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
  • Microsoft — Re54L7V (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • bruteratel.com (report)
  • proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
  • insights.bridewell.com — Cyber%20Threat%20Intelligence%20Report%202025 (report)
  • Trend Micro — Black Basta Infiltrates Networks Via Qakbot Brute Ratel And Coba (report)
  • blog.eclecticiq.com — Inside Intelligence Center Lunar Spider Enabling Ransomware Attacks On Financial Sector With Brute Ratel C4 And Latrodectus (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Brute Ratel C4 (report)
  • blog.spookysec.net — Analyzing Brc4 Badgers (report)
  • michaelkoczwara.medium.com — Hunting C2 With Shodan 223Ca250D06F (report)
  • 0xdarkvortex.dev — Hiding In Plainsight (report)
  • blog.krakz.fr — Latrodectus (report)
  • bruteratel.com — Pe Reflection Long Live The King (report)
  • socradar.io — Brute Ratel Utilized By Threat Actors In New Ransomware Operations (report)
  • cybergeeks.tech — A Deep Dive Into Brute Ratel C4 Payloads (report)
  • twitter.com — 1652067563545800705 (report)
  • blog.reveng.ai — Latrodectus Distribution Via Brc4 (report)
  • splunk.com — Deliver A Strike By Reversing A Badger Brute Ratel Detection And Analysis (report)
  • twitter.com — 1580030303950995456 (report)
  • protectedmo.de — Brute (report)
  • protect.airbus.com — Incident Response Analysis Of Recent Version Of Brc4 (report)
  • medium.com — Brute Ratel Config Decoding Update 7820455022Cb (report)
  • web.archive.org — Hunting Cyber Evil Ratels From The Targeted Attacks To The Widespread Usage Of Brute Ratel (report)

External references