Bifrost, also known as Bifrose, is a long-running backdoor malware family first identified in the early 2000s. It originally targeted Windows systems, but later variants were developed for Unix-like and Linux environments, including ELF samples associated with intrusions against East Asian targets. The malware is strongly associated with the China-linked espionage group BlackTech, which is assessed to have obtained and enhanced the source code around 2010 and subsequently used it across multiple campaigns, including Shrouded Crossbow.
In BlackTech operations, Bifrost has been used as a remote-access backdoor for espionage and post-compromise persistence. Reported variants support command-and-control communications, remote shell access, file operations, and host reconnaissance. Unix and Linux variants have been observed collecting system information such as operating system and kernel details and timezone data, and some samples communicate over Tor or SSL depending on the branch. Bifrost-derived tooling in the Shrouded Crossbow cluster was used alongside related backdoors such as KIVARS and XBOW against government contractors, privatized agencies, and enterprises in sectors including consumer electronics, computing, healthcare, and finance.
Delivery in BlackTech-linked campaigns has been tied to spearphishing with decoy documents and right-to-left override disguised attachments, while some reporting also places Bifrost-family tooling on infrastructure used in broader exploitation-led intrusions against network edge devices and servers. The family remains notable for its longevity, cross-platform adaptation, and continued reuse in Chinese cyber-espionage activity targeting organizations in Taiwan, Japan, Hong Kong, and related regional interests.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
TeamT5 released a blog post detailing an intrusion at a Taiwan academic institution attributed to BlackTech utilizing the Ghostcat vulnerability, (CVE-2020-1938) for initial access. | The file later found on the compromised institution’s network was identified as a Unix variant of Bifrose, or Bifrost, a backdoor associated with BlackTech.
Around May 2022, JPCERT/CC confirmed an attack activity against Japanese organizations that exploited F5 BIG-IP vulnerability (CVE-2022-1388). The targeted organizations have confirmed that data in BIG-IP has been compromised.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE CANAL ... Tools ... Bifrose, Deuterbear, DRIGO, Flagpro, Gh0stTimes, KIVARS, PLEAD, Spiderpig, Waterbear, XBOW
Shrouded Crossbow employs three BIFROST-derived backdoors: BIFROSE, KIVARS, and XBOW.
•TSCookie •Waterbear •Bifrose •Consock •LAMICE •BUSYICE •BTSDOOR •DELTABEEF •SPIDERPIG
7 distinct techniques documented for this family, organized by ATT&CK tactic.
BlackTech is best known for utilizing network and software exploits for initial access... TeamT5 released a blog post detailing an intrusion at a Taiwan academic institution attributed to BlackTech utilizing the Ghostcat vulnerability, (CVE-2020-1938) for initial access.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
Specifically, upon gaining an initial foothold into a target network and gaining administrator access to network edge devices, BlackTech cyber actors often modify the firmware to hide their activity across the edge devices to further maintain persistence in the network.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the BRONZE CANAL threat profile.
Custom malware used by BlackTech in campaigns involving compromised routers and stealthy persistence.
A long-running backdoor originally targeting Windows and later observed as an ELF/Linux variant. The sample discussed includes hard-coded C2 infrastructure, supports communication with a command-and-control server, and performs host reconnaissance such as checking OS version, kernel version, and timezone.
Malware used by BlackTech and found on the attacker-controlled server alongside the BIG-IP exploit code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.