ATT&CKSoftwareBrute Ratel C4

Brute Ratel C4

S1063

Tool.View on attack.mitre.org

About this tool

Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.

Techniques used33

Procedure examples33

TechniqueProcedure example
T1005
Data from Local System

Brute Ratel C4 has the ability to upload files from a compromised system.

T1021
Remote Services

Brute Ratel C4 has the ability to use RPC for lateral movement.

T1021.002
SMB/Windows Admin Shares

Brute Ratel C4 has the ability to use SMB to pivot in compromised networks.

T1021.006
Windows Remote Management

Brute Ratel C4 can use WinRM for pivoting.

T1027
Obfuscated Files or Information

Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory.

T1027.007
Dynamic API Resolution

Brute Ratel C4 can call and dynamically resolve hashed APIs.

T1036.005
Match Legitimate Resource Name or Location

Brute Ratel C4 has used a payload file named OneDrive.update to appear benign.

T1036.008
Masquerade File Type

Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files.

T1046
Network Service Discovery

Brute Ratel C4 can conduct port scanning against targeted systems.

T1047
Windows Management Instrumentation

Brute Ratel C4 can use WMI to move laterally.

T1055.002
Portable Executable Injection

Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts.

T1057
Process Discovery

Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs).

T1059.003
Windows Command Shell

Brute Ratel C4 can use cmd.exe for execution.

T1069.002
Domain Groups

Brute Ratel C4 can use `net group` for discovery on targeted domains.

T1071.001
Web Protocols

Brute Ratel C4 can use HTTPS and HTTPS for C2 communication.

View all 33 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. Dark Vortex Brute Ratel C4 Open source
    Dark Vortex. (n.d.). A Customized Command and Control Center for Red Team and Adversary Simulation. Retrieved February 7, 2023.
  2. MDSec Brute Ratel August 2022 Open source
    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.
  3. Palo Alto Brute Ratel July 2022 Open source
    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.
  4. SANS Brute Ratel October 2022 Open source
    Thomas, W. (2022, October 5). Cracked Brute Ratel C4 framework proliferates across the cybercriminal underground. Retrieved February 6, 2023.
  5. Trend Micro Black Basta October 2022 Open source
    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.