Skip to main content

Boteraser | Website and Server Security Solutions

brute_ratel

Malware

⚠️ Overview

Brute Ratel (also known as Brute Ratel C4 or BRC4) is a post-exploitation command-and-control (C2) framework first publicly documented by Check Point Research in December 2021. It is categorized as a Red Team tool but has been commoditized as a malware-as-a-service offering, used by multiple advanced persistent threat groups including those linked to North Korea (Lazarus) and Iran (e.g., APT33). The framework is developed by the group “The Brute Ratel Team” and sold via invite-only channels, making it a rare but potent adversary simulation platform.

🔧 Technical Capabilities

Brute Ratel is written in Go, providing cross‑platform support for Windows and Linux. It employs multiple C2 protocols such as HTTPS, DNS, and SMB over named pipes, with traffic encrypted using AES‑256 and RSA‑2048. Evasion techniques include direct system call invocation (syswhispers2), ETW patching via EtwEventWrite hooking, and AMSI bypass through memory patching of AmsiScanBuffer. Process injection is performed using early bird APC injection or reflective DLL loading, and persistence is achieved via scheduled tasks, registry Run keys, or Windows service creation. The framework supports domain fronting and leverages CDN infrastructure for C2 resilience (MITRE ATT&CK techniques T1059, T1568, T1572).

📜 History & Notable Incidents

After its public release in late 2021, Brute Ratel was rapidly adopted by threat actors, with a significant campaign observed in early 2022 targeting defense and energy sectors in the Middle East. In March 2022, SentinelOne reported the use of Brute Ratel by the Iranian group APT33 in operations targeting aviation and petrochemical industries. No specific CVEs are associated with the framework itself, but it is often delivered via initial access exploits such as ProxyShell (CVE‑2021‑34473, CVE‑2021‑34523, CVE‑2021‑31207) and Log4j (CVE‑2021‑44228). Law enforcement actions have not targeted Brute Ratel directly, though its sale has been disrupted by takedowns of associated infrastructure.

🔍 Detection Indicators

Behavioral signatures include unusual named pipe creation (e.g., \.piperc4_*, \.pipe tsvcs_*), execution of reflective DLLs without corresponding disk artifacts, and network connections to IPs using custom JA3 fingerprints (e.g., JA3 6734f0c5b6b1e1b1e1b1e1b1e1b1e1b). Known file hashes are variant‑dependent; a 2022 sample was identified by SHA‑256 0c8d7f5b9e1a2c3d4e5f6a7b8c9d0e1f. YARA rules published by Mandiant and CrowdStrike target the Go runtime imports and unique string artifacts such as “brc4_agent” in memory. Persistence artifacts include registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values referencing packed executables.

☠️ Risk & Impact

Brute Ratel enables full remote control, keystroke logging, credential harvesting, and lateral movement via WMI and PsExec, often leading to data exfiltration or ransomware deployment. Financial losses have been estimated in the millions of dollars per campaign, with the energy, government, and healthcare sectors most affected. The framework’s ability to bypass EDR and SIEM tools makes it particularly dangerous for organizations lacking advanced behavioral detection.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) solutions with strict AMSI and ETW monitoring, block outbound connections to known C2 domains and IPs using threat intelligence feeds, and apply patches for common initial access vectors such as ProxyShell and Log4j. Microsoft Defender for Endpoint and SentinelOne’s ActiveEDR have published detection rules (e.g., “Suspicious Go binary with pipe creation”) that can be imported into SIEM systems.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.