Netskope Threat Labs

Bifrost

ATP Sandbox Adv. HeuristicsAV

Bifrost is a remote access trojan that has been active since 2004 and gives operators backdoor control over infected Windows systems. It supports file management, process control, and payload downloads, and its long development history has produced many variants that evade outdated detection signatures. Cyberattackers distribute it through spam, exploit kits, and bundled installers, and its persistence and feature set have kept it in circulation for two decades.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Backdoor.Bifrost
Generic.Bifrost.44B821B9
Generic.Bifrost.709709EB
Linux.Backdoor.Bifrost
Win32.Backdoor.Bifrost
Win64.Backdoor.Bifrost