Brutus is a botnet-associated brute-force toolset used in large-scale password-spraying and credential attacks against remote access infrastructure and enterprise authentication surfaces. It has been linked to campaigns targeting Remote Access VPN services on Cisco Secure Firewall devices, as well as devices from Fortinet, Palo Alto, and SonicWall, and web applications that rely on Active Directory authentication. Reported operations have involved a globally distributed pool of more than 20,000 IP addresses and rotation of source IPs after a small number of login attempts to reduce blocking and detection.
Observed tradecraft indicates use for credential-based initial access rather than exploitation of software vulnerabilities. Brutus has been associated with attempts to authenticate using stolen or brute-forced credentials, including activity tied to ScreenConnect access in intrusions associated with ransomware operations. Its use in password spraying across many accounts with shared passwords, combined with infrastructure scale and IP rotation, makes it suited for broad reconnaissance of exposed authentication services and opportunistic compromise. Attribution of Brutus operators remains inconclusive, although some reporting has noted limited infrastructure overlap with activity previously associated with APT29. That overlap is not sufficient for firm attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Bezpečnostní výskumníci Aaron Martin a Chris Grube zverejnili informácie, že táto aktivita môže súvisieť s botnetom „Brutus“, ktorý v súčasnosti využíva viac ako 20 000 IP adries po celom svete.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Pokiaľ väčšie množstvá pokusov smerujú z rovnakých IP adries a záznamy obsahujú aj úspešné prihlásenie z nich, môže ísť o vážny bezpečnostný incident.
Pokusy o prihlásenie boli zaznamenané do služby VPN so vzdialeným prístupom (RAVPN) nakonfigurované v zariadeniach Cisco Secure Firewall.
To implement sticky keys detection, we built two separate modes ... compares a baseline bitmap of the RDP login screen against a second bitmap captured after sending five Shift key scancodes, if a rectangular region of significantly changed pixels appears (the telltale sign of a cmd.exe or PowerShell window popping up), the heuristic flags it as a likely backdoor ...
Pokiaľ väčšie množstvá pokusov smerujú z rovnakých IP adries a záznamy obsahujú aj úspešné prihlásenie z nich, môže ísť o vážny bezpečnostný incident.
To implement sticky keys detection, we built two separate modes ... compares a baseline bitmap of the RDP login screen against a second bitmap captured after sending five Shift key scancodes, if a rectangular region of significantly changed pixels appears (the telltale sign of a cmd.exe or PowerShell window popping up), the heuristic flags it as a likely backdoor ...
"We uncover a vulnerability allowing non-root access to IMU data via an IOKit driver... BRUTUS achieves a character-level accuracy of 89.1% to 97.5% in key recovery."
In this design, the Rust module functions as a purely functional, I/O-free state machine that handles all complex protocol logic, including X.224 negotiation, CredSSP sequencing, etc. while Go manages the network I/O, TLS handshakes, and connection lifecycle.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Brutus is a brute force tool used to perform password attacks, likely to facilitate initial access for further malware deployment.
Botnet associated with facilitating initial access by using stolen or brute-forced credentials via ScreenConnect, potentially linked to Cicada3301 operations.
Brutus is a botnet linked in the report to large-scale password-spraying attacks against VPN services and web applications using Active Directory authentication. It rotates IP addresses every six attempts to evade detection and blocking and uses specific non-public usernames.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.