logo

Linux Variants of Bifrost Trojan Evade Detection via Typosquatting

ID: b81b8acb-f752-540c-a85b-877cc58c3ad8

STIX ID: report--b81b8acb-f752-540c-a85b-877cc58c3ad8

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-03-07

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

**Bifrost RAT resurgence:** Researchers observed new Linux (and ARM) variants of the long‑running Bifrost remote access Trojan using typosquatted C2 infrastructure (e.g., download.vmfare.com) and active samples (>100 instances), with associated IPs and domains provided as IoCs; recommended mitigations include NGFW, URL filtering, malware prevention and cloud visibility tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.