Campaign record
Brute Ratel C4, then Latrodectus
Brute Ratel C4 and Latrodectus delivered by HTML attachments with a fake error dialog
- Status as last assessed
- Active
- First seen
- 2024-09-20
- Last seen
- 2024-09-20
- Indicators
- 10
- Sources
- 1
- Targets
- Windows
- Fake error dialog
- Brute Ratel C4
- Latrodectus
- HTML email attachment
Original research
- Proofpoint2024-11-14Vendor researchFirst account
Security Brief: ClickFix Social Engineering Technique Floods Threat Landscape
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Proofpoint dated this to 20 September 2024 and named no actor for it, recording only a resemblance to earlier TA571 and TA578 work. Delivery was an HTML file attached to mail written around routine commercial matters — budgets, invoicing, consignment paperwork — sent from a spread of addresses. Opened locally, the attachment drew a fabricated error panel offering one remedial button. Pressing it put a base64-wrapped instruction on the clipboard, and a further panel asked the reader to run that from the Windows Run box. What came back was a DLL, which started Brute Ratel C4; Latrodectus followed from there. Attachment names were a fixed word and then random digits, and the page source had been written backwards to slow anyone examining it. The published indicators are three Brute Ratel control domains, three addresses, two Latrodectus domains, and the address the DLL was fetched from.
What changed since publication
The accounts above describe these indicators as they were on the day each was written. We re-check them ourselves and record every check, including the ones that find nothing — which is the only reason the gaps below can be stated rather than hidden.
- Indicators checked
- 3 of 10
- Checks recorded
- 6
- Checks since publication
- 6
- Never checked
- 7
Observation window 2026-08-10 to 2026-08-22. Checks are sampled, not continuous; the sampling policy is on /methodology. 7 indicators have never been checked by us at all.
Current recorded state
- 3 Unregistered
- 7 Not checked by us
Nothing has changed state between our first check and our most recent one. A domain that still resolves is not necessarily still serving anything — registrar hold pages answer DNS indefinitely, which is why the state above distinguishes “parked or suspended” from “resolving”.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is Windows Run dialog (T1204.004), which 23 of the 44 published campaigns in this corpus also record (52%).
Indicators
10 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account or any overlap with another campaign in this corpus. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Brute Ratel C4, then Latrodectus”, campaign ID 64eb116f, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/64eb116f/brute-ratel-c4-latrodectus-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.