The Phantom Menace: Brute Ratel remains rare and targeted

Brute Ratel remains rare and targeted, with limited real-world use and far fewer detections than Cobalt Strike. Sophos notes that cracked versions and targeted deployments have kept it from becoming the widespread threat feared, while defenders continue to monitor and block its activity. #BruteRatel #CobaltStrike #Meterpreter #PowerSploit #Sliver

Keypoints

  • Brute Ratel has been rarely observed in the wild and is mainly seen in well-resourced, targeted campaigns.
  • Public exposure and a 2022 crack did not lead to broad adoption; Sophos telemetry shows very few Brute Ratel detections Sept 2022–Mar 2023.
  • Cobalt Strike remains far more prevalent, with thousands of detections and incidents during the same period.
  • A Polish government cyberespionage campaign reportedly used Brute Ratel alongside Cobalt Strike, prompting updated detections.
  • Brute Ratel is a post-exploitation tool requiring initial access (e.g., phishing attachments or exploiting server vulnerabilities) to be effective.
  • Detections often arise from generic malware behavior or blocked C2 activities; widespread evasion claims have not been broadly borne out in practice.

MITRE Techniques

  • [T1566.001] Phishing – Initial Access via email attachments that install an attack payload when opened. β€œ[email attachments that install an attack payload when opened]”.
  • [T1190] Exploit Public-Facing Application – Initial Access via exploiting existing vulnerabilities on an Internet-exposed server. β€œ[existing vulnerabilities on an Internet-exposed server]”.
  • [T1021.002] SMB/Windows Admin Shares – Internal Badger-to-Badger communications can be over TCP and the SMB file-sharing protocol. β€œ[Badger-to-Badger communications can be over TCP and the SMB file-sharing protocol]”.
  • [T1071.001] Web Protocols – Command and control traffic to the C2 server uses HTTP/HTTPS. β€œ[communications back to the C2 server are over web protocols (HTTP and HTTPS)]”.
  • [T1071.004] DNS – DNS over HTTPS (DOH) used in communication with C2. β€œ[DNS over HTTPS (DOH)]”.
  • [T1055] Process Injection – The script injected the β€œbadger” implant code into notepad.exe. β€œ[injected the β€œbadger” implant code into notepad.exe]”.
  • [T1027] Obfuscated/Compressed Files and Information – The delivery script was highly obfuscated JS. β€œ[highly obfuscated JS which injected the β€œbadger” implant code into notepad.exe]”.

Indicators of Compromise

  • [Domain] – prefectrespond.online – example domain used for C2 communications. prefectrespond[.]online/share.php
  • [Domain] – instrumentation-database-fc-lows.trycloudflare.com – example domain used for C2 communications. instrumentation-database-fc-lows[.]trycloudflare.com/share[.]php
  • [IP Address] – 5.161.100.208 – C2-related activity hosted on a German ISP. 5.161.100.208
  • [File] – Temp1_Julie Ramzel_1040_1120s 2019-2021.zip – delivery archive associated with the campaign. Temp1_Julie Ramzel_1040_1120s 2019-2021.zip
  • [File] – passwords_Julie Ramzel_1040_1120s 2019-2021.js – obfuscated JS script contained in the ZIP archive. passwords_Julie_Ramzel_1040_1120s_2019-2021.js

Read more: https://news.sophos.com/en-us/2023/05/18/the-phantom-menace-brute-ratel-remains-rare-and-targeted/