Bifrost is a long-running malware name applied to multiple distinct tools, most prominently a Windows remote-access backdoor family and later BIFROST-derived espionage backdoors used by East Asia-focused threat actors. The classic Windows Bifrost family emerged in the mid-2000s as a three-component remote administration trojan consisting of a server, builder, and client, enabling remote control of infected systems. Documented capabilities include arbitrary command execution, remote shell access, file upload and download, file deletion, process management, password extraction, keystroke logging, screen capture, webcam capture, registry editing, and host control actions such as reboot or shutdown. Some variants also incorporated rootkit-style hiding and configurable persistence options.
Bifrost has also appeared in targeted intrusion activity as a backdoor lineage adapted for espionage operations. Shrouded Crossbow, assessed as linked to BlackTech, used enhanced BIFROST-derived malware including BIFROSE, KIVARS, and XBOW against government contractors and organizations in sectors such as consumer electronics, computing, healthcare, and finance, especially in East Asia. Reported delivery in those campaigns included spearphishing with decoy documents and right-to-left override disguised attachments. Derived variants expanded functionality with features such as screenshot capture, keylogging, file download and execution, and support for 64-bit environments.
A Linux version of the BiFrost backdoor has also been documented in activity attributed to HUAPI, also known as PLEAD, a China-linked espionage actor known for targeting Taiwan and other regional victims. That Linux variant functioned as a backdoor supporting file transfer and management, process execution and termination, and remote shell operations, with communications protected using a modified RC4-based scheme. In that reporting, the malware was associated with compromise of vulnerable internet-facing infrastructure and subsequent use as a malware distribution or control point.
Because the name Bifrost is also used for an unrelated macOS Kerberos offensive-security tool, references to “Bifrost” require context to avoid conflating separate software families. In malware usage, Bifrost is best understood as a backdoor lineage with Windows origins that later influenced multiple espionage-oriented derivatives across Windows and UNIX-like platforms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TeamT5 released a blog post detailing an intrusion at a Taiwan academic institution attributed to BlackTech utilizing the Ghostcat vulnerability, (CVE-2020-1938) for initial access.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign, first observed in 2010, is believed to be operated by a well-funded group given how it appeared to have purchased the source code of the BIFROST backdoor, which the operators enhanced and created other tools from.
該惡意程式為 Linux 版本的 BiFrost 後門程式,其版本號為 5.0.0.0。根據 TeamT5 長期研究的情資顯示,該惡意程式為中國駭客組織 HUAPI(又名為 PLEAD)慣用的後門程式。
該惡意程式為 Linux 版本的 BiFrost 後門程式,其版本號為 5.0.0.0。根據 TeamT5 長期研究的情資顯示,該惡意程式為中國駭客組織 HUAPI(又名為 PLEAD)慣用的後門程式。
19 distinct techniques documented for this family, organized by ATT&CK tactic.
BlackTech is best known for utilizing network and software exploits for initial access... TeamT5 released a blog post detailing an intrusion at a Taiwan academic institution attributed to BlackTech utilizing the Ghostcat vulnerability, (CVE-2020-1938) for initial access.
經過逆向分析,該惡意後門程式具有上傳/下載/列舉/刪除/搬移檔案(File)、執行/結束程序(Process)、開啟/關閉遠端命令列介面程式(Remote Shell)等功能
In addition to the hard-coded IP addresses, standard strings indicating first contact with the C&C server, notably unix| , 5.0.0.0| , and what appear to be C&C commands (recvData and send data), are visible in the output.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux variant of the BiFrost backdoor disguised as a PNG file but actually a UNIX ELF executable. It supports file upload/download/list/delete/move, process execution/termination, and opening/closing a remote shell. Its C2 traffic uses a modified RC4 algorithm for encryption.
A macOS Kerberos attack tool written in Objective-C to interact with the Heimdal krb5 API.
A backdoor whose source code was reportedly acquired and enhanced to create BIFROSE, KIVARS, and XBOW.
A Windows backdoor trojan family that uses a server-builder-client architecture to provide remote attackers arbitrary code execution on infected systems. Capabilities include process and file management, password extraction, keystroke logging, screen and webcam capture, registry editing, remote shell access, and persistence/rootkit options.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.