logo

New BIFROSE Linux Malware Variant Using Deceptive VMware Domain for Evasion

ID: 33e37b6f-8914-54d6-bfb9-fe8086a93929

STIX ID: report--33e37b6f-8914-54d6-bfb9-fe8086a93929

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-03-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Palo Alto Unit 42 researchers identified a new Linux variant of the long-running Bifrost RAT that disguises its C2 as a VMware-like domain (download.vmfare.com), uses a Taiwan public DNS resolver (168.95.1.1), and shows a spike in activity since October 2023 with 104 artifacts and an ARM build; the malware is associated with the state-linked BlackTech group and is distributed via email attachments, malicious websites, and multi-stage loaders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.