How attackers use Brute Ratel (BRC4) by Lucie Cardiet
ID: 1293b3b4-a8f8-57ac-b8a2-752cd972c09f
STIX ID: report--1293b3b4-a8f8-57ac-b8a2-752cd972c09f
Feed Name: Vectra AI Blog
Threat Score
This report describes Brute Ratel C4 (BRC4), a sophisticated post-exploitation command-and-control framework abused by real-world attackers, detailing its stealth and evasion features (userland unhooking, sleep masking, indirect syscalls), flexible payload and listener configurations, credential theft and lateral movement techniques, fileless/process injection capabilities, and Vectra AI’s detection approaches mapped to the MITRE ATT&CK framework.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
