Brute Ratel (also known as Brute Ratel C4 or BRC4) is a post-exploitation command-and-control (C2) framework first publicly documented by Check Point Research in December 2021. It is categorized as a Red Team tool but has been commoditized as a malware-as-a-service offering, used by multiple advanced persistent threat groups including those linked to North Korea (Lazarus) and Iran (e.g., APT33). The framework is developed by the group “The Brute Ratel Team” and sold via invite-only channels, making it a rare but potent adversary simulation platform.
Brute Ratel is written in Go, providing cross‑platform support for Windows and Linux. It employs multiple C2 protocols such as HTTPS, DNS, and SMB over named pipes, with traffic encrypted using AES‑256 and RSA‑2048. Evasion techniques include direct system call invocation (syswhispers2), ETW patching via EtwEventWrite hooking, and AMSI bypass through memory patching of AmsiScanBuffer. Process injection is performed using early bird APC injection or reflective DLL loading, and persistence is achieved via scheduled tasks, registry Run keys, or Windows service creation. The framework supports domain fronting and leverages CDN infrastructure for C2 resilience (MITRE ATT&CK techniques T1059, T1568, T1572).
After its public release in late 2021, Brute Ratel was rapidly adopted by threat actors, with a significant campaign observed in early 2022 targeting defense and energy sectors in the Middle East. In March 2022, SentinelOne reported the use of Brute Ratel by the Iranian group APT33 in operations targeting aviation and petrochemical industries. No specific CVEs are associated with the framework itself, but it is often delivered via initial access exploits such as ProxyShell (CVE‑2021‑34473, CVE‑2021‑34523, CVE‑2021‑31207) and Log4j (CVE‑2021‑44228). Law enforcement actions have not targeted Brute Ratel directly, though its sale has been disrupted by takedowns of associated infrastructure.
Behavioral signatures include unusual named pipe creation (e.g., \.piperc4_*, \.pipe tsvcs_*), execution of reflective DLLs without corresponding disk artifacts, and network connections to IPs using custom JA3 fingerprints (e.g., JA3 6734f0c5b6b1e1b1e1b1e1b1e1b1e1b). Known file hashes are variant‑dependent; a 2022 sample was identified by SHA‑256 0c8d7f5b9e1a2c3d4e5f6a7b8c9d0e1f. YARA rules published by Mandiant and CrowdStrike target the Go runtime imports and unique string artifacts such as “brc4_agent” in memory. Persistence artifacts include registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values referencing packed executables.
Brute Ratel enables full remote control, keystroke logging, credential harvesting, and lateral movement via WMI and PsExec, often leading to data exfiltration or ransomware deployment. Financial losses have been estimated in the millions of dollars per campaign, with the energy, government, and healthcare sectors most affected. The framework’s ability to bypass EDR and SIEM tools makes it particularly dangerous for organizations lacking advanced behavioral detection.
Defenders should deploy endpoint detection and response (EDR) solutions with strict AMSI and ETW monitoring, block outbound connections to known C2 domains and IPs using threat intelligence feeds, and apply patches for common initial access vectors such as ProxyShell and Log4j. Microsoft Defender for Endpoint and SentinelOne’s ActiveEDR have published detection rules (e.g., “Suspicious Go binary with pipe creation”) that can be imported into SIEM systems.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.