LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S1063: Brute Ratel C4

Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.[1][2][3][4][5]

EnterpriseS1063ToolObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Brute Ratel C4 matters because it is a commercial red-team/adversary simulation tool designed to challenge EDR and AV visibility, with Windows agents (“badgers”) that can support command execution, lateral movement, privilege escalation, persistence, discovery, collection, and command-and-control behaviors. For leaders, the decision value is not the tool name alone: it is whether the organization can detect and investigate stealthy post-compromise activity that may look like legitimate administration, web/DNS traffic, or normal Windows management.

Executive priority

Prioritize this as a resilience and readiness test for Windows endpoint, identity, network, and SOC operations. ATT&CK provides no official detection guidance for this software entry, so executives should ask whether current controls can prove coverage across the related behaviors: remote services and admin shares, WinRM/WMI execution, domain account and group discovery, suspicious C2 over web/DNS/non-application protocols, tool transfer, process injection, masquerading, and local data collection. This is also useful audit evidence: defensive teams should be able to show telemetry exists, alerts are tuned, and incident responders have playbooks for stealthy red-team-style tooling that may be abused outside authorized testing.

Technical view

Validate behavior-based detection rather than relying only on product or filename signatures. The object is a Windows tool, but many related ATT&CK techniques span other platforms; start with Windows coverage for the tool and use the related techniques to guide broader enterprise checks. SOC and IR teams should correlate endpoint process, command-line, module/API, file, registry, authentication, SMB, WinRM, WMI, DNS, proxy, firewall, and EDR telemetry. High-value behavior chains include malicious-file execution followed by obfuscated payload activity, native API or PE injection, domain/user/group discovery, network service discovery, lateral movement through SMB admin shares or WinRM, ingress tool transfer, local data collection or screen capture, and C2 over HTTP/S, DNS, web services, or non-application-layer protocols.

Likely telemetry

  • Windows endpoint process creation and command-line events, including cmd.exe and administrative tool usage
  • EDR/AV prevention and detection events, including suspicious memory, injection, and evasion indicators
  • WMI and WinRM operational logs and remote execution evidence
  • Windows authentication logs, especially domain logons and remote service access
  • SMB and Windows admin share access records

Detection direction

  • Use behavior correlations across the related techniques instead of a single indicator-based rule, because the official description notes the tool was designed to avoid EDR and AV capabilities and no official ATT&CK detection text is provided.
  • Tune for suspicious combinations: user-opened file or new executable, obfuscation/deobfuscation, unusual child processes, API-heavy execution, process injection, discovery commands, and outbound C2-like traffic.
  • Baseline legitimate administration for SMB admin shares, WinRM, WMI, domain enumeration, and network service discovery; these are common false-positive areas but become higher-risk when paired with new binaries, unusual source hosts, or external communications.
  • Review DNS, web, and non-application-protocol egress visibility, since related C2 techniques include Web Protocols, DNS, Web Service, and Non-Application Layer Protocol.
  • Confirm detection engineering covers masquerading and file-type mismatch behaviors, not just known hashes or names.

Mitigation priorities

  • Establish strict governance for any approved adversary simulation tooling, including authorization, scope, logging, and post-test evidence review.
  • Harden Windows remote administration paths: restrict SMB admin shares, WinRM, and WMI usage to approved administrators and management hosts.
  • Strengthen identity controls around domain accounts and groups, including least privilege and monitoring for unusual enumeration or remote logon patterns.
  • Improve egress control and monitoring for web, DNS, web service, and unusual protocol communications from endpoints.
  • Ensure endpoint controls are configured to monitor memory/injection, suspicious API usage, obfuscated files, masquerading, and unauthorized tool transfer.
Additional notes and limits

This take is based on the ATT&CK software entry for Brute Ratel C4 and its supplied relationships. The most defensible defensive approach is to map coverage to the related techniques: execution through command shell, WMI, native API, malicious files; lateral movement through remote services, SMB admin shares, and WinRM; discovery; evasion through obfuscation, masquerading, dynamic API resolution, and PE injection; collection; ingress transfer; and C2 over web, DNS, web services, and other protocols.

ATT&CK does not provide official detection guidance or tactics directly on this software object, and the supplied platform for the tool is Windows. Relationship techniques include broader platforms, but those should not be treated as proof that this specific tool operates on every related platform. Local validation is required to determine actual telemetry quality, alert coverage, false positives, and authorized red-team usage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Brute Ratel C4

Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.[1][2][3][4][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

33 rows
DomainIDNameRelationship / procedure
EnterpriseT1055.002Portable Executable InjectionSub-technique

Brute Ratel C4 has injected Latrodectus into the Explorer.exe process on comrpomised hosts.[6]

EnterpriseT1569.002Service ExecutionSub-technique

Brute Ratel C4 can create Windows system services for execution.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

Brute Ratel C4 can use cmd.exe for execution.[2]

EnterpriseT1021.006Windows Remote ManagementSub-technique

Brute Ratel C4 can use WinRM for pivoting.[2]

EnterpriseT1113Screen Capture

Brute Ratel C4 can take screenshots on compromised hosts.[2]

EnterpriseT1057Process Discovery

Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs).[2]

EnterpriseT1027Obfuscated Files or Information

Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory.[2][3]

EnterpriseT1047Windows Management Instrumentation

Brute Ratel C4 can use WMI to move laterally.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Brute Ratel C4 has used a payload file named OneDrive.update to appear benign.[2]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Brute Ratel C4 has the ability to use SMB to pivot in compromised networks.[2][3][1]

EnterpriseT1005Data from Local System

Brute Ratel C4 has the ability to upload files from a compromised system.[2]

EnterpriseT1140Deobfuscate/Decode Files or Information

Brute Ratel C4 has the ability to deobfuscate its payload prior to execution.[2]

EnterpriseT1069.002Domain GroupsSub-technique

Brute Ratel C4 can use `net group` for discovery on targeted domains.[5]

EnterpriseT1572Protocol Tunneling

Brute Ratel C4 can use DNS over HTTPS for C2.[2][5]

EnterpriseT1518.001Security Software DiscoverySub-technique

Brute Ratel C4 can detect EDR userland hooks.[2]

EnterpriseT1685Disable or Modify Tools

Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI).[2][3]

EnterpriseT1036.008Masquerade File TypeSub-technique

Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files.[2]

EnterpriseT1087.002Domain AccountSub-technique

Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery.[2][5]

EnterpriseT1021Remote Services

Brute Ratel C4 has the ability to use RPC for lateral movement.[2]

EnterpriseT1620Reflective Code Loading

Brute Ratel C4 has used reflective loading to execute malicious DLLs.[3]

EnterpriseT1046Network Service Discovery

Brute Ratel C4 can conduct port scanning against targeted systems.[2]

EnterpriseT1482Domain Trust Discovery

Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery.[2][5]

EnterpriseT1106Native API

Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion.[2][3]

EnterpriseT1102Web Service

Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams.[2]

EnterpriseT1071.004DNSSub-technique

Brute Ratel C4 can use DNS over HTTPS for C2.[2][5]

EnterpriseT1095Non-Application Layer Protocol

Brute Ratel C4 has the ability to use TCP for external C2.[2]

EnterpriseT1105Ingress Tool Transfer

Brute Ratel C4 can download files to compromised hosts.[2][6]

EnterpriseT1027.007Dynamic API ResolutionSub-technique

Brute Ratel C4 can call and dynamically resolve hashed APIs.[2]

EnterpriseT1497.003Time Based ChecksSub-technique

Brute Ratel C4 can call `NtDelayExecution` to pause execution.[2][3]

EnterpriseT1574.001DLLSub-technique

Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO.[2] Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe.[2]

EnterpriseT1558.003KerberoastingSub-technique

Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking.[2]

EnterpriseT1204.002Malicious FileSub-technique

Brute Ratel C4 has gained execution through users opening malicious documents.[2]

EnterpriseT1071.001Web ProtocolsSub-technique

Brute Ratel C4 can use HTTPS and HTTPS for C2 communication.[2][5]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
298aa28db36c23d6...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle298aa28db36c…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Dark Vortex Brute Ratel C4

    Dark Vortex. (n.d.). A Customized Command and Control Center for Red Team and Adversary Simulation. Retrieved February 7, 2023.

    Open source URL
  2. [2]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  3. [3]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  4. [4]
    SANS Brute Ratel October 2022

    Thomas, W. (2022, October 5). Cracked Brute Ratel C4 framework proliferates across the cybercriminal underground. Retrieved February 6, 2023.

    Open source URL
  5. [5]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  6. [6]
    Rapid7 Fake W2 July 2024

    Elkins, T. (2024, July 24). Malware Campaign Lures Users With Fake W2 Form. Retrieved September 13, 2024.

    Open source URL
  7. [7]
    BRc4

    (Citation: Palo Alto Brute Ratel July 2022)

  8. [8]
    BRc4

    (Citation: Palo Alto Brute Ratel July 2022)

  9. [9]
    BRc4

    (Citation: Palo Alto Brute Ratel July 2022)

  10. [10]
    Dark Vortex Brute Ratel C4

    Dark Vortex. (n.d.). A Customized Command and Control Center for Red Team and Adversary Simulation. Retrieved February 7, 2023.

    Open source URL
  11. [11]
    Dark Vortex Brute Ratel C4

    Dark Vortex. (n.d.). A Customized Command and Control Center for Red Team and Adversary Simulation. Retrieved February 7, 2023.

    Open source URL
  12. [12]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  13. [13]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  14. [14]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  15. [15]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  16. [16]
    SANS Brute Ratel October 2022

    Thomas, W. (2022, October 5). Cracked Brute Ratel C4 framework proliferates across the cybercriminal underground. Retrieved February 6, 2023.

    Open source URL
  17. [17]
    SANS Brute Ratel October 2022

    Thomas, W. (2022, October 5). Cracked Brute Ratel C4 framework proliferates across the cybercriminal underground. Retrieved February 6, 2023.

    Open source URL
  18. [18]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  19. [19]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  20. [20]
    mitre-attackS1063
    Open source URL
  21. [21]
    mitre-attackS1063
    Open source URL
  22. [22]
    mitre-attackS1063
    Open source URL
  23. [23]
    Rapid7 Fake W2 July 2024

    Elkins, T. (2024, July 24). Malware Campaign Lures Users With Fake W2 Form. Retrieved September 13, 2024.

    Open source URL
  24. [24]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  25. [25]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  26. [26]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  27. [27]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  28. [28]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  29. [29]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  30. [30]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  31. [31]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  32. [32]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  33. [33]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  34. [34]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  35. [35]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  36. [36]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  37. [37]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  38. [38]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  39. [39]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  40. [40]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  41. [41]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  42. [42]
    Dark Vortex Brute Ratel C4

    Dark Vortex. (n.d.). A Customized Command and Control Center for Red Team and Adversary Simulation. Retrieved February 7, 2023.

    Open source URL
  43. [43]
    Dark Vortex Brute Ratel C4

    Dark Vortex. (n.d.). A Customized Command and Control Center for Red Team and Adversary Simulation. Retrieved February 7, 2023.

    Open source URL
  44. [44]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  45. [45]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  46. [46]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  47. [47]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  48. [48]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  49. [49]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  50. [50]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  51. [51]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  52. [52]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  53. [53]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  54. [54]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  55. [55]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  56. [56]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  57. [57]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  58. [58]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  59. [59]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  60. [60]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  61. [61]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  62. [62]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  63. [63]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  64. [64]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  65. [65]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  66. [66]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  67. [67]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  68. [68]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  69. [69]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  70. [70]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  71. [71]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  72. [72]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  73. [73]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  74. [74]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  75. [75]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  76. [76]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  77. [77]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  78. [78]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  79. [79]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  80. [80]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  81. [81]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  82. [82]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  83. [83]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  84. [84]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  85. [85]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  86. [86]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  87. [87]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  88. [88]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  89. [89]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  90. [90]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  91. [91]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  92. [92]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  93. [93]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  94. [94]
    Rapid7 Fake W2 July 2024

    Elkins, T. (2024, July 24). Malware Campaign Lures Users With Fake W2 Form. Retrieved September 13, 2024.

    Open source URL
  95. [95]
    Rapid7 Fake W2 July 2024

    Elkins, T. (2024, July 24). Malware Campaign Lures Users With Fake W2 Form. Retrieved September 13, 2024.

    Open source URL
  96. [96]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  97. [97]
    MDSec Brute Ratel August 2022

    Chell, D. PART 3: How I Met Your Beacon – Brute Ratel. Retrieved February 6, 2023.

    Open source URL
  98. [98]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  99. [99]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  100. [100]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  101. [101]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  102. [102]
    Palo Alto Brute Ratel July 2022

    Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

    Open source URL
  103. [103]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.