Brute Ratel C4 (BRC4) is a commercial command-and-control and post-exploitation framework developed by Chetan Nayak and first released in 2020 for authorized penetration testing and red-team operations. Its implants, known as badgers, establish command-and-control connections and provide remote access, command execution, and support for lateral movement. Although legitimate offensive-security software, it is also abused in ransomware and espionage operations. Observed users include Black Basta, the China-nexus intrusion set Earth Lamia, and Nobelium, also known as Midnight Blizzard. The framework is used after initial compromise rather than as an exploit-generation tool.
Malicious deployments target Windows systems and have used phishing lures, resume-themed disk images, private loaders, and follow-on delivery through QakBot, Bumblebee, and Latrodectus. Execution chains abuse legitimate applications through DLL search-order hijacking and sideloading, decrypt embedded shellcode, and execute implants in memory, including within other Windows processes. Brute Ratel can detect EDR userland hooks, and analyzed shellcode stagers perform anti-debugging checks. Some versions protect embedded payloads and configuration data with RC4 encryption and dynamically derived keys. Attackers have also deployed the framework following exploitation of SAP NetWeaver vulnerability CVE-2025-31324 to maintain persistent access. Its reuse across criminal and state-linked operations means its presence alone does not establish attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This maximum severity unrestricted file upload vulnerability allowed attackers to deploy JSP web shells and execute commands remotely via simple HTTP requests, making it accessible even to attackers with limited technical expertise. | The SAP NetWeaver zero-day (CVE-2025-31324) exemplifies this, as attackers used varied “exploitation twists”—deploying tools like “Brute Ratel” for stealthy command-and-control (C2).
The infection occurred within hours after the mass exploitation of webshells deployed on compromised NetWeaver instances started and involved the use of the Brute Ratel C2 framework.
... a subsequent attack involved the deployment of the Brute Ratel C2 framework using inline MSBuild task execution.
32 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We also found another DLL sideloading loader used by Earth Lamia to execute Brute Ratel shellcode.
Recently, our Unit 42 incident response team was engaged in a Black Basta breach response that uncovered several tools and malware samples on the victim's machines, including GootLoader malware, Brute Ratel C4 red-teaming tool and an older PlugX malware sample.
Threat actors spread malicious ISOs... The in-memory code, Brute Ratel C4, starts to communicate with IP 174.129.157[.]251 on TCP port 443... The threat actors can remotely access the infected device once the Brute Ratel has been loaded in order to run commands and spread farther throughout the compromised network.
References https://medium.com/@knownsec404team/the-patchwork-group-has-updated-its-arsenal-launching-attacks-for-the-first-time-using-brute-ratel-175741987d87
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The shellcode-based loader is stored onboard and is loaded into memory. The shellcode stager uses a few Anti Debugging checks such as checking the NtGlobalFlag.
Upon clicking Roshan-Bandara_CV_Dialog, cmd[.]exe is launched: /c start OneDriveUpdater[.]exe
The malicious version.dll file has an embedded unencrypted shellcode in its .data section that will be copied to an allocated memory address space with the PAGE_EXECUTE_READ protection to then be executed using the callback function of the EnumChildWindows Windows API.
When the victim mounts the ISO and executes the onedrive_fotos.exe binary, it will load the maliciously crafted version.dll.
Brute Ratel was retrieved from an external server and was leveraged to inject malicious code into the compromised system’s memory.
Process Injection (QAPC, CreateRemoteThread, and CreateSection Techniques)
The simulated code will look for a cmd.exe process and inject shellcode that will execute a calc.exe.
Figure 11 shows the code function that duplicates the token of “winlogon.exe” or “logonui.exe” and uses that token to a new process using CreateProcessWithTokenW API.
Brute Ratel was retrieved from an external server and was leveraged to inject malicious code into the compromised system’s memory.
Process Injection (QAPC, CreateRemoteThread, and CreateSection Techniques)
The simulated code will look for a cmd.exe process and inject shellcode that will execute a calc.exe.
Another interesting feature of the BRC4 DLL agent is that it can evade Event Tracing for Windows (ETW) and AMSI Windows mechanisms by patching known API responsible for generating or tracing system events. Figure 12 shows the code of this DLL agent that patches “EtwEventWrite” API with “0xC3” opcode.
Figure 11 shows the code function that duplicates the token of “winlogon.exe” or “logonui.exe” and uses that token to a new process using CreateProcessWithTokenW API.
Figure 11 shows the code function that duplicates the token of “winlogon.exe” or “logonui.exe” and uses that token to a new process using CreateProcessWithTokenW API.
BRC4 is also capable of spoofing the parent process (PPID) for its newly created process to evade detections that are based on parent/child process relationships.
It then uses the restored key to decrypt the rest of the data and has the original Cobalt Strike shellcode execute in memory.
Figure 14 shows the code snippet of the function that enumerates Address Resolution Protocol (ARP) entries or physical address map table for IPV4 on the local system using the GetIpNetTable Windows API.
Check the active and idle session of the user in the target host
The encoded onboard DLL is still stored RC4 encrypted... the RC4 key for the config is no longer the hardcoded value in the DLL. Instead, it is now the last 8 bytes from the decoded DLL blob.
The current version of Brute Ratel allows users to create command-and-control channels using legitimate tools such as Microsoft Teams, Slack and Discord. | Brute Ratel (BRc4) is a Command and Control (C2) framework designed to help attackers evade defence systems and remain undetected while executing malicious commands.
176 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
121 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named only in a reference link related to process injection behavior; no direct discussion of the malware/tool itself in the content.
Referenced as a follow-on payload delivered by Latrodectus after initial compromise.
Associated Analytic Story ... Remcos Trickbot Brute Ratel C4 RedLine Stealer PlugX MoonPeak WhisperGate
Mentioned as a commercial offensive tool with architectural and tradecraft similarities to the analyzed framework. Its actual use in the reported intrusion is not established.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.