Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Brute Ratel C4 has the ability to upload files from a compromised system. |
| T1021 Remote Services |
Brute Ratel C4 has the ability to use RPC for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
Brute Ratel C4 has the ability to use SMB to pivot in compromised networks. |
| T1021.006 Windows Remote Management |
Brute Ratel C4 can use WinRM for pivoting. |
| T1027 Obfuscated Files or Information |
Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory. |
| T1027.007 Dynamic API Resolution |
Brute Ratel C4 can call and dynamically resolve hashed APIs. |
| T1036.005 Match Legitimate Resource Name or Location |
Brute Ratel C4 has used a payload file named OneDrive.update to appear benign. |
| T1036.008 Masquerade File Type |
Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files. |
| T1046 Network Service Discovery |
Brute Ratel C4 can conduct port scanning against targeted systems. |
| T1047 Windows Management Instrumentation |
Brute Ratel C4 can use WMI to move laterally. |
| T1055.002 Portable Executable Injection |
Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts. |
| T1057 Process Discovery |
Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs). |
| T1059.003 Windows Command Shell |
Brute Ratel C4 can use cmd.exe for execution. |
| T1069.002 Domain Groups |
Brute Ratel C4 can use `net group` for discovery on targeted domains. |
| T1071.001 Web Protocols |
Brute Ratel C4 can use HTTPS and HTTPS for C2 communication. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.