logo

New Bifrost malware for Linux mimics VMware domain for evasion

ID: 778a9905-23ac-597d-b61a-bf34886c6462

STIX ID: report--778a9905-23ac-597d-b61a-bf34886c6462

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-02-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Unit 42 researchers report a new, stealthier Linux variant of the long-standing Bifrost RAT that uses a deceptive VMware-like C2 domain (download.vmfare.com), resolves via a Taiwan public DNS resolver, ships as stripped binaries, exfiltrates collected host data (hostname, IP, process IDs) encrypted with RC4 over TCP, and now includes ARM builds; 104 new samples were captured since October, signaling active distribution and broadened targeting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.