ATT&CKReferencesPalo Alto Brute Ratel July 2022

Palo Alto Brute Ratel July 2022

Harbison, M. and Renals, P. (2022, July 5). When Pentest Tools Go Brutal: Red-Teaming Tool Being Abused by Malicious Actors. Retrieved February 1, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolBrute Ratel C4

Brute Ratel C4 has the ability to upload files from a compromised system.

T1021
Remote Services
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use RPC for lateral movement.

T1021.002
SMB/Windows Admin Shares
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use SMB to pivot in compromised networks.

T1021.006
Windows Remote Management
ToolBrute Ratel C4

Brute Ratel C4 can use WinRM for pivoting.

T1027
Obfuscated Files or Information
ToolBrute Ratel C4

Brute Ratel C4 has used encrypted payload files and maintains an encrypted configuration structure in memory.

T1027.007
Dynamic API Resolution
ToolBrute Ratel C4

Brute Ratel C4 can call and dynamically resolve hashed APIs.

T1036.005
Match Legitimate Resource Name or Location
ToolBrute Ratel C4

Brute Ratel C4 has used a payload file named OneDrive.update to appear benign.

T1036.008
Masquerade File Type
ToolBrute Ratel C4

Brute Ratel C4 has used Microsoft Word icons to hide malicious LNK files.

T1046
Network Service Discovery
ToolBrute Ratel C4

Brute Ratel C4 can conduct port scanning against targeted systems.

T1047
Windows Management Instrumentation
ToolBrute Ratel C4

Brute Ratel C4 can use WMI to move laterally.

T1057
Process Discovery
ToolBrute Ratel C4

Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs).

T1059.003
Windows Command Shell
ToolBrute Ratel C4

Brute Ratel C4 can use cmd.exe for execution.

T1071.001
Web Protocols
ToolBrute Ratel C4

Brute Ratel C4 can use HTTPS and HTTPS for C2 communication.

T1071.004
DNS
ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

T1087.002
Domain Account
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery.

T1095
Non-Application Layer Protocol
ToolBrute Ratel C4

Brute Ratel C4 has the ability to use TCP for external C2.

T1102
Web Service
ToolBrute Ratel C4

Brute Ratel C4 can use legitimate websites for external C2 channels including Slack, Discord, and MS Teams.

T1105
Ingress Tool Transfer
ToolBrute Ratel C4

Brute Ratel C4 can download files to compromised hosts.

T1106
Native API
ToolBrute Ratel C4

Brute Ratel C4 can call multiple Windows APIs for execution, to share memory, and defense evasion.

T1113
Screen Capture
ToolBrute Ratel C4

Brute Ratel C4 can take screenshots on compromised hosts.

T1140
Deobfuscate/Decode Files or Information
ToolBrute Ratel C4

Brute Ratel C4 has the ability to deobfuscate its payload prior to execution.

T1204.002
Malicious File
ToolBrute Ratel C4

Brute Ratel C4 has gained execution through users opening malicious documents.

T1482
Domain Trust Discovery
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries and `nltest /domain_trusts` for domain trust discovery.

T1497.003
Time Based Checks
ToolBrute Ratel C4

Brute Ratel C4 can call `NtDelayExecution` to pause execution.

T1518.001
Security Software Discovery
ToolBrute Ratel C4

Brute Ratel C4 can detect EDR userland hooks.

T1558.003
Kerberoasting
ToolBrute Ratel C4

Brute Ratel C4 can decode Kerberos 5 tickets and convert it to hashcat format for subsequent cracking.

T1569.002
Service Execution
ToolBrute Ratel C4

Brute Ratel C4 can create Windows system services for execution.

T1572
Protocol Tunneling
ToolBrute Ratel C4

Brute Ratel C4 can use DNS over HTTPS for C2.

T1574.001
DLL
ToolBrute Ratel C4

Brute Ratel C4 has used search order hijacking to load a malicious payload DLL as a dependency to a benign application packaged in the same ISO. Brute Ratel C4 has loaded a malicious DLL by spoofing the name of the legitimate Version.DLL and placing it in the same folder as the digitally-signed Microsoft binary OneDriveUpdater.exe.

T1685
Disable or Modify Tools
ToolBrute Ratel C4

Brute Ratel C4 has the ability to hide memory artifacts and to patch Event Tracing for Windows (ETW) and the Anti Malware Scan Interface (AMSI).

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.