TF-MAL-elf.brute_ratel
📛 Threat Title
Malware family: brute_ratel
Description
ThreatFox malware family `elf.brute_ratel`. Printable name: brute_ratel.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Brute Ratel C4 Badger Used to Load Latrodectus Editor's note: The current article is authored by Mohamed Talaat, a cybersecurity researcher and malware analyst. You can find Mohamed on X and LinkedIn. Brute Ratel C4 (BRC4) is a customized, commercial command and control (C2) framework that was first introduced in December 2020.
-
web:attack.mitre.org
Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement ...
-
web:blog.reveng.ai
The malware borrows code heavily from the open-source BlackLotus malware [2], which contains a ready-to-use bot and command-and-control (C2) component. Latrodectus was one of the many malware families targeted by Operation Endgame, an international law enforcement effort against malware loader infrastructure [5].
-
web:malpedia.caad.fkie.fraunhofer.de
Brute Ratel C4 (BRC4) is a commercial framework for red-teaming and adversarial attack simulation, which made its first appearance in December 2020. It was specifically designed to evade detection by endpoint detection and response (EDR) and antivirus (AV) capabilities.
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with win.brute_ratel_c4.
-
web:unit42.paloaltonetworks.com
Pentest and adversary emulation tool Brute Ratel C4 is effective at defeating modern detection capabilities - and malicious actors have begun to adopt it.
-
web:www.microsoft.com
Disconnect the infected device from all networks (both wired and wireless) to sever the command-and-control connection. Use your security software to quarantine and remove identified malicious files, such as the initial LNK, side-loaded DLLs, and memory-resident payloads. As a last resort ...
-
web:www.protect.airbus.com
During our latest incident response case we have discovered a recent sample of Brute Ratel C4 packed with Themida.
-
web:www.quorumcyber.com
Additionally, Brute Ratel C4 is a malware as a service, therefore resulting in a vast scope of exploitability. The malware is primarily distributed via phishing emails and exploiting Dynamic Link Library (DLL) hijacking vulnerabilities in Windows operating systems.
-
web:www.securityscientist.net
Learn what Brute Ratel C4 is, how APT29 and ransomware groups abuse it, its EDR evasion capabilities, IOCs, detection methods, and how to defend against it.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.