Brute Ratel C4 (BRc4) is a dual-use red-team framework, not malware by definition. In a July 2022 account of Palo Alto Networks Unit 42 findings, however, researchers described BRc4 in an intrusion chain that used an ISO file, DLL order hijacking and process injection. They judged sanctioned penetration testing highly unlikely, but the reporting did not establish who operated the activity.
What the 2022 report said happened
SecurityWeek reported on July 7, 2022, that Unit 42 researchers identified an ISO file containing a Windows shortcut (LNK), a malicious DLL and a copy of the Microsoft OneDrive Updater. The account described the legitimate-looking updater being used to load the malicious DLL through DLL order hijacking. That technique takes advantage of how a program searches for a library it needs, causing it to load an attacker-controlled file instead.
After loading, the payload reportedly used undocumented Windows NTAPI calls to inject a process into RuntimeBroker.exe. The researchers also said BRc4 code was reconstructed in memory through multiple push and mov instructions. These are details in SecurityWeek’s summary of Unit 42’s findings, not an independently verified analysis of the underlying sample. SecurityWeek, July 7, 2022.
Why researchers considered authorized testing unlikely
The account described an AWS-hosted IP address communicating with BRc4 and connections from a Ukrainian IP address that researchers thought likely administered the command-and-control infrastructure. Potential victims included an organization in Argentina, an IP television provider serving North and South American content, and a textile manufacturer in Mexico.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Unit 42 researchers collectively wrote: “Given the geographic dispersion of these victims, the upstream connection to a Ukrainian IP and several other factors, we believe it is highly unlikely that BRc4 was deployed in support of legitimate and sanctioned penetration testing activities.” This is the researchers’ assessment based on the reported context; it is not proof of a particular operator or government.
What the evidence does—and does not—say about attribution
SecurityWeek compared the ISO packaging method with techniques associated with Cozy Bear/APT29. Similarity in a technique does not establish that APT29 carried out this activity. The available account does not conclusively identify the operator, so describing the activity as definitively conducted by a named nation-state actor goes beyond what it supports.
The distinction matters: BRc4’s presence and the researchers’ assessment that authorized testing was unlikely concern the tool and circumstances observed. They do not, by themselves, reveal who was behind the operation.
BRc4 is dual-use software
BRc4 was described as a red-teaming and adversarial attack simulation framework made for legitimate security testing but capable of abuse. SecurityWeek’s 2022 article said it had been released in December 2020 and characterized its sophistication as similar to Cobalt Strike. The article also reported a price of $2,500 for a one-year, single-user license at that time; that is a historical figure, not current product or pricing information.
Rank #3
How to interpret the sample and VirusTotal details
SecurityWeek reported that a sample submitted to VirusTotal in May was not marked malicious by any scanning engine at the time. The report did not provide a denominator, sample hash or scan date, and this historical observation is not a statement about current detection. It also said Unit 42 identified seven additional BRc4 samples dating back to February 2021. That is a count in the researchers’ reported sample set, not a measure of campaign size or broader prevalence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Later BRc4 reports are separate activity
Other coverage described Qakbot delivering BRc4 as a second-stage payload in activity associated with Black Basta. Separately, Positive Technologies reported that BRc4 version 1.4.5 was leaked onto the dark web in July 2024, and cited a possible July 2024 attack targeting Bhutan attributed to Patchwork/APT-C-09. These reports concern different activity and do not identify the operator of the 2022 case.
Rank #4
For the later leak and Bhutan-related account, see Positive Technologies’ BRc4 analysis. The 2022 incident details and the later reports should be read as separate claims with their respective attribution qualifiers.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →

