Brute Ratel C4, also known as BRc4, is a commercial adversary simulation and red-teaming framework for Windows environments that has also been abused by threat actors in real-world intrusions. It is designed to evade modern defensive controls and has been used for command-and-control and post-exploitation activity after initial compromise. Reported malicious use includes phishing-driven delivery chains in which victims are lured to download an installer that deploys BRc4, followed by installation of additional malware such as Latrodectus. One observed campaign used tax-themed social engineering and fake document-signing pages, and was attributed to the initial access broker Storm-0249. In those operations, BRc4 functioned as an intermediate post-compromise tool within a broader intrusion chain rather than as a standalone commodity payload. The framework is therefore best characterized as a Windows post-exploitation platform and backdoor-capable C2 tool that can support follow-on attacker actions while blending with legitimate red-team tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRc4 is an advanced adversary simulation and red-teaming framework designed to bypass modern security defenses, but it has also been exploited by threat actors for post-exploitation activities and C2 operations.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft has observed several phishing campaigns using tax-related themes for social engineering to steal credentials and deploy malware.
The campaign used tax-themed emails that attempted to deliver the red-teaming tool BRc4 and Latrodectus malware... The emails contained a PDF attachment...
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an incorrect classification for the sample; the content explicitly states the sample is not BruteRatel C4.
Post-exploitation tool deployed via phishing campaigns delivered through RaccoonO365.
Commercial/legitimate red-teaming framework abused by threat actors for post-exploitation and command-and-control; designed to evade/bypass modern defenses.
An adversary simulation and red-teaming framework abused by threat actors for post-exploitation and command-and-control operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.