Security News > 2024 > February > New Bifrost malware for Linux mimics VMware domain for evasion

New Bifrost malware for Linux mimics VMware domain for evasion
2024-02-29 21:36

A new Linux variant of the Bifrost remote access trojan employs several novel evasion techniques, including the use of a deceptive domain that was made to appear as part of VMware.

The analysis of the latest Bitfrost samples by Unit 42 researchers has uncovered several interesting updates that enhance the malware's operational and evasion capabilities.

First, the command and control server the malware connects to uses the "Download.vmfare[.]com" domain, which appears similar to a legitimate VMware domain, allowing it to be easily missed during inspection.

Another new finding highlighted in Unit 42's report is an ARM version of Bitfrost, which has the same functionality as the x86 samples analyzed in the write-up.

FBI seizes Warzone RAT infrastructure, arrests malware vendor.

Hackers used new Windows Defender zero-day to drop DarkMe malware.


News URL

https://www.bleepingcomputer.com/news/security/new-bifrost-malware-for-linux-mimics-vmware-domain-for-evasion/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 11 64 2312 1489 67 3932
Vmware 146 11 222 256 102 591