s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.bifrost

📛 Threat Title

Malware family: Bifrost

Category: Bifrost First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.bifrost`. Printable name: Bifrost. Aliases: elf.bifrose.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.bifrost VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrost

IOC database

Type
domain
Value
elf.bifrost
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.bifrost

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrost

domain elf.bifrose VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrose

IOC database

Type
domain
Value
elf.bifrose
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.bifrost

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrose

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    The evolving nature of Bifrost RAT, coupled with the adoption of deceptive domain strategies, underscores the persistent threat posed by this malware . Observations of a surge in Bifrost activity highlight the importance of proactive detection and efforts to sensitive data and protect against unauthorized access.

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities. In 2025 alone, security researchers detected ...

  • web:en.wikipedia.org

    Bifrost is a backdoor trojan horse family of more than 10 variants which can infect Windows 95 through Windows 10 (although on modern Windows systems, after Windows XP, its functionality is limited).

  • web:grokipedia.com

    Tools like Microsoft's Process Explorer can reveal hidden processes associated with Bifrost , such as server.exe running in memory without visible windows, aiding manual inspection on infected systems. Mitigation involves a combination of automated scans and manual removal steps to eradicate the malware and prevent reinfection.

  • web:hackread.com

    The latest version of Bifrost RAT employs sophisticated techniques including typosquatting, to avoid detection and complicate efforts to trace its origins. Cybersecurity experts at Palo Alto Networks' Unit 42 have uncovered a new cybersecurity threat: a new variant of the Bifrost RAT (also known as Bifrose) targeting Linux systems. This variant, utilizing a tricky domain named download ...

  • web:thehackernews.com

    Cybersecurity researchers have discovered a new Linux variant of a remote access trojan (RAT) called BIFROSE (aka Bifrost ) that uses a deceptive domain mimicking VMware. "This latest version of Bifrost aims to bypass security measures and compromise targeted systems," Palo Alto Networks Unit 42 researchers Anmol Maurya and Siddharth Sharma said.

  • web:unit42.paloaltonetworks.com

    The RAT Bifrost has a new Linux variant that leverages a deceptive domain in order to compromise systems. We analyze this expanded attack surface.

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.hivepro.com

    Counteracting malware like Bifrost is critical to protecting sensitive data and maintaining the security of computer systems, underscoring the importance of continuous monitoring and mitigation efforts.

  • web:www.threatvirus.com

    Suggestions for Mitigation Implement robust email security measures to prevent phishing attacks and block malicious attachments. Regularly update and patch software and systems to address known vulnerabilities exploited by Bifrost RAT. Deploy advanced endpoint detection and response (EDR) solutions capable of identifying and mitigating fileless malware and evasion techniques. Conduct ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.