TF-MAL-elf.bifrost
📛 Threat Title
Malware family: Bifrost
Description
ThreatFox malware family `elf.bifrost`. Printable name: Bifrost. Aliases: elf.bifrose.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.bifrost
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrost
IOC database
- Type
- domain
- Value
elf.bifrost- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.bifrost
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrost
domain
elf.bifrose
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrose
IOC database
- Type
- domain
- Value
elf.bifrose- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.bifrost
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.bifrose
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The evolving nature of Bifrost RAT, coupled with the adoption of deceptive domain strategies, underscores the persistent threat posed by this malware . Observations of a surge in Bifrost activity highlight the importance of proactive detection and efforts to sensitive data and protect against unauthorized access.
-
web:cybersecuritynews.com
Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities. In 2025 alone, security researchers detected ...
-
web:en.wikipedia.org
Bifrost is a backdoor trojan horse family of more than 10 variants which can infect Windows 95 through Windows 10 (although on modern Windows systems, after Windows XP, its functionality is limited).
-
web:grokipedia.com
Tools like Microsoft's Process Explorer can reveal hidden processes associated with Bifrost , such as server.exe running in memory without visible windows, aiding manual inspection on infected systems. Mitigation involves a combination of automated scans and manual removal steps to eradicate the malware and prevent reinfection.
-
web:hackread.com
The latest version of Bifrost RAT employs sophisticated techniques including typosquatting, to avoid detection and complicate efforts to trace its origins. Cybersecurity experts at Palo Alto Networks' Unit 42 have uncovered a new cybersecurity threat: a new variant of the Bifrost RAT (also known as Bifrose) targeting Linux systems. This variant, utilizing a tricky domain named download ...
-
web:thehackernews.com
Cybersecurity researchers have discovered a new Linux variant of a remote access trojan (RAT) called BIFROSE (aka Bifrost ) that uses a deceptive domain mimicking VMware. "This latest version of Bifrost aims to bypass security measures and compromise targeted systems," Palo Alto Networks Unit 42 researchers Anmol Maurya and Siddharth Sharma said.
-
web:unit42.paloaltonetworks.com
The RAT Bifrost has a new Linux variant that leverages a deceptive domain in order to compromise systems. We analyze this expanded attack surface.
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
-
web:www.hivepro.com
Counteracting malware like Bifrost is critical to protecting sensitive data and maintaining the security of computer systems, underscoring the importance of continuous monitoring and mitigation efforts.
-
web:www.threatvirus.com
Suggestions for Mitigation Implement robust email security measures to prevent phishing attacks and block malicious attachments. Regularly update and patch software and systems to address known vulnerabilities exploited by Bifrost RAT. Deploy advanced endpoint detection and response (EDR) solutions capable of identifying and mitigating fileless malware and evasion techniques. Conduct ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.