ATT&CKReferencesMDSec Brute Ratel August 2022

MDSec Brute Ratel August 2022

Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use SMB to pivot in compromised networks.

T1027
Obfuscated Files or Information
ToolBrute Ratel C4

Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory.

T1106
Native API
ToolBrute Ratel C4

Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion.

T1497.003
Time Based Checks
ToolBrute Ratel C4

Brute Ratel C4 can call `NtDelayExecution` to pause execution.

T1620
Reflective Code Loading
ToolBrute Ratel C4

Brute Ratel C4 has used reflective loading to execute malicious DLLs.

T1685
Disable or Modify Tools
ToolBrute Ratel C4

Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.