Linux Variants of Bifrost Trojan Evade Detection via Typosquatting
ID: b81b8acb-f752-540c-a85b-877cc58c3ad8
STIX ID: report--b81b8acb-f752-540c-a85b-877cc58c3ad8
Feed Name: Dark Reading
Threat Score
Date Published: 2024-03-07
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
...
...
**Bifrost RAT resurgence:** Researchers observed new Linux (and ARM) variants of the long‑running Bifrost remote access Trojan using typosquatted C2 infrastructure (e.g., download.vmfare.com) and active samples (>100 instances), with associated IPs and domains provided as IoCs; recommended mitigations include NGFW, URL filtering, malware prevention and cloud visibility tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
