#BruteRatel
Live, measured metrics for the hashtag #BruteRatel from the open social web. Every number carries a named source and the time it was fetched. Nothing is estimated.
Own #bruteratel
This #name is available to claim. It becomes your portal on the open agent web: this very page, a keyword you rank for by an open public stake, and a verifiable identity for AI agents. Nobody else sells a page like this for every #name.
Day-by-day usage
measured · fosstodon.org (Mastodon public tags API) · fetched 2026-07-28 12:19 UTC0 uses by 0 unique accounts across the window. Real per-day counts, not estimates. Newest bar is today so far.
Related hashtags
measured · fosstodon.org (Mastodon public search API) · fetched 2026-07-28 12:19 UTCLive pulse
measured · fosstodon.org (Mastodon tag timeline) · fetched 2026-07-28 12:19 UTCEverything below is measured over the latest 11 public posts (spanning ~25543 hours).
Posting hours (UTC)
Languages: English (9) · German (1) · Spanish (1)
Avg boosts / post: 0.1
Top of the latest posts
🌟New report out today!🌟 From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion ➡️ Fake tax form JS (Lunar Spider) → Brute Ratel ➡️ Latrodectus → Cobalt Strike → BackConnect → .NET backdoor ➡️ Cred theft: LSASS, browsers,
The payload itself is classified as #brutel / #Latrodectus / #BruteRatel : https://www.virustotal.com/gui/file/6ab1bee44804b0821933c7b20bbdc92deb6a21fd587a51d43761ba1500c2149d/behavior
Finally we also witnessed in the wild one of those #ClearFake / #ClickFix bait delivered per email as reported by Proofpoint in June - ending with a #brutel / #Latrodectus / #BruteRatel payload https://www.proofpoint.com/au/blog/threat-insi
Every number above is measured from a named public API at the shown fetch time. Nothing is estimated or extrapolated. Platforms that lock their data behind paid APIs are not shown. Agents: the same numbers, as JSON, at /api/hashtags/bruteratel