Skip to main content

This dangerous hacking tool is now on the loose, and the consequences could be huge

A dangerous post-exploitation toolkit, first used for cybersecurity purposes, has now been cracked and leaked to hacking communities.

The toolkit is being shared across many different websites, and the potential repercussions could be huge now that it can fall into the hands of various threat actors.

Brute Ratel logo.
Bleeping Computer

This could be bad. The post-exploitation toolkit in question, called Brute Ratel C4, was initially created by Chetan Nayak. Nayak is an ex-red teamer, meaning that his job included attempting to breach the securities of a given network, which was being actively defended by those on the blue team. Afterward, both teams discuss how it went and whether there are some security flaws to improve upon.

Brute Ratel was created for that exact purpose. It was made for “red teamers” to use, with the ultimate purpose of being able to execute commands remotely on a compromised network. This would then grant the attacker access to the rest of the network in an easier way.

Cobalt Strike is seen as a similar tool to Brute Ratel, and that tool has been heavily abused by ransomware gangs, which is why it’s fairly easy to detect. Brute Ratel has not been quite as widely spread up until now, and it has a licensing verification system that mostly kept the hackers at bay. Nayak is able to revoke the license of any company found to be fake or misusing the tool.

Unfortunately, that’s now a thing of the past, because a cracked version of the tool started to circulate. It was first uploaded to VirusTotal in its uncracked state, but a Russian group called Molecules was able to crack it and entirely remove the licensing requirement from it. This means that now, any potential hacker can get their hands on it if they know where to look.

Will Thomas, a cyber threat intelligence researcher, published a report on the cracked version of the tool. It has already spread to many English and Russian-speaking communities, including CryptBB, RAMP, BreachForums, Exploit[.]in, Xss[.]is, and Telegram and Discord groups.

Person typing on a computer keyboard.
Image used with permission by copyright holder

“There are now multiple posts on multiple of the most populated cybercrime forums where data brokers, malware developers, initial access brokers, and ransomware affiliates all hang out,” said Thomas in the report. In a conversation with Bleeping Computer, Thomas said that the tool works and no longer requires a license key.

Thomas explained the potential dangers of the tech, saying, “One of the most concerning aspects of the BRC4 tool for many security experts is its ability to generate shellcode that is undetected by many EDR and AV products. This extended window of detection evasion can give threat actors enough time to establish initial access, begin lateral movement, and achieve persistence elsewhere.”

Knowing that this powerful tool is out there, in the hands of hackers who should never have gained access to it, is definitely scary. Let’s hope that antivirus software developers can tighten the defenses against Brute Ratel soon enough.

Editors' Recommendations

Monica J. White
Monica is a UK-based freelance writer and self-proclaimed geek. A firm believer in the "PC building is just like expensive…
These are the best AIO liquid coolers for your PC in 2023
Corsair H100i AIO installed on a CPU.

An all-in-one (AIO) liquid cooler not only guarantees quieter cooling for your CPU compared to a conventional air cooler, but can also facilitate in reducing temperatures to an extent that allows for overclocking. AIOs provide a straightforward method for water-cooling your PC without the hassle of dealing with messy components selection. We also advise considering a liquid cooler, especially if you already own or intend to acquire a high-performance processor like an Intel Core i9-13900K or AMD's Ryzen 7950x.

Most builds call for a 240mm AIO. However, you can go up or down depending on your PC build size or cooling needs, too, with various options available.

Read more
This Alienware gaming PC with an RTX 4090 is $500 off today
Alienware Aurora R15 placed at an angle on a table.

If you're planning to invest in gaming PC deals, you should expect to shell out a significant amount of cash if you want a powerful machine. You have the chance at enjoying huge savings along the way though, through offers like Dell's discount for the Alienware Aurora R15. Instead of the gaming desktop's sticker price of $3,700, you'll only have to pay $3,200 -- it's still not what you'd call affordable, but the $500 in savings will go a long way towards building your setup as you can spend it on monitor deals and video games. You need to push through with the purchase today though, as we're not sure if the offer will still be around tomorrow.

Why you should buy the Alienware Aurora R15 gaming desktop
The Alienware Aurora R15 looks out of this world, but that's not the only reason why the machine is in our list of the best gaming PCs. Inside the stylish exterior are the 13th-generation Intel Core i9 processor, the Nvidia GeForce RTX 4090 graphics card, and 32GB of RAM. With these specifications, not only can you play the best PC games at their highest settings, but you'll also be prepared for all of the best upcoming PC games. When the time comes that you need faster components, the tool-less design of the Alienware Aurora R15 will make it easy to upgrade its RAM and GPU.

Read more
Dell’s cheapest business laptop is 50% off today
Dell Latitude 3420 on a desk hooked up to a monitor.

Not all laptop deals will get you a machine that's designed to keep up with work activities. If you're looking for a business laptop, here's a recommendation -- the Dell Latitude 3420, which is on sale from Dell at 50% off. From its sticker price of $1,244, it will be yours for just $619. It's a steal to purchase this device with $625 in savings, so you wouldn't want to miss this chance. The limited-time offer may end at any moment though, so don't hesitate in completing the transaction if you're interested in this laptop.

Why you should buy the Dell Latitude 3420 laptop
The Dell Latitude 3420 laptop is powered by the 11th-generation Intel Core i3 processor and 8GB of RAM. It's not as fast as the best laptops with the latest generation of processors and more RAM, but it's more than enough for handling daily tasks like creating reports and building presentations. The device, however, ships with Windows 11 Pro in its 256GB SSD, so you'll have access to more of the operating system's features. The Dell Latitude 3420 also comes with a 14-inch Full HD display, for a clear look at the details of the projects that you'll be handling.

Read more