logo

How attackers use Brute Ratel (BRC4) by Lucie Cardiet

ID: 1293b3b4-a8f8-57ac-b8a2-752cd972c09f

STIX ID: report--1293b3b4-a8f8-57ac-b8a2-752cd972c09f

Feed Name: Vectra AI Blog

Threat Score
75/100

Date Published: 2025-05-14

Date Updated: 2026-05-01

...
...

This report describes Brute Ratel C4 (BRC4), a sophisticated post-exploitation command-and-control framework abused by real-world attackers, detailing its stealth and evasion features (userland unhooking, sleep masking, indirect syscalls), flexible payload and listener configurations, credential theft and lateral movement techniques, fileless/process injection capabilities, and Vectra AI’s detection approaches mapped to the MITRE ATT&CK framework.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.