Shrouded Crossbow is a long-running cyber espionage campaign assessed to be operated by BlackTech, a threat actor associated with operations against East Asian targets, particularly Taiwan. The campaign has been observed since 2010 and is linked with other BlackTech activity clusters including PLEAD and Waterbear through overlapping infrastructure, coordinated victimology, and co-occurrence on the same compromised environments. Its apparent objective is the theft of sensitive documents and other intelligence from government-related and commercial targets. Shrouded Crossbow has targeted privatized agencies, government contractors, and enterprises in the consumer electronics, computer, health care, and financial sectors. The campaign relies heavily on malware derived from the BIFROST backdoor, principally BIFROSE, KIVARS, and XBOW. BIFROSE includes command-and-control communications over Tor and has included variants for UNIX-based operating systems. KIVARS supports file download and execution, drive enumeration, screenshot capture, keylogging control, window manipulation, malware service removal, and simulated mouse and keyboard input. XBOW combines capabilities associated with BIFROSE and KIVARS. Initial compromise has been associated with spear-phishing using malicious attachments disguised with right-to-left override techniques and paired with decoy documents. The tooling and tradecraft indicate a well-resourced operator that acquired and further developed BIFROST source code for sustained espionage use. Across the broader BlackTech intrusion set linked to this campaign, operators have also demonstrated credential theft, exfiltration, persistence, in-memory loading, process injection, and the use of compromised edge infrastructure to support operations. Known related clusters and tooling include PLEAD, DRIGO, and Waterbear.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage campaign using BIFROST-derived backdoors against government contractors and multiple private-sector industries to steal sensitive information.
A named BlackTech campaign/toolset centered on BIFROST-derived backdoors, specifically BIFROSE, KIVARS, and XBOW.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.