1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / tool

Brute Ratel C4 — Attack Tool

Brute Ratel C4 is a commercial red-teaming and adversarial attack simulation tool that first appeared in December 2020. Brute Ratel C4 was specifically designed to avoid detection by endpoint detection and response (EDR) and antivirus (AV) capabilities, and deploys agents called badgers to enable arbitrary command execution for lateral movement, privilege escalation, and persistence. In September 2022, a cracked version of Brute Ratel C4 was leaked in the cybercriminal underground, leading to its use by threat actors.

Tool identity and evidence

Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.

Aliases: Brute Ratel C4, BRc4

Primary tool reference

Existing author guides

No reviewed association in this snapshot.

Primary documentation

No reviewed association in this snapshot.

Connected ecosystem references

Linked tags

Technique-specific simulations and detections

Detection links describe the associated behavior, not independently verified tool-specific signatures.

Telemetry context

Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.