KIVARS is a BIFROST-derived backdoor associated with the China-linked espionage group BlackTech, also tracked as BRONZE CANAL and Shrouded Crossbow. It has been used in long-running cyber espionage operations targeting organizations in East Asia, especially Taiwan, including government contractors and enterprises in sectors such as consumer electronics, computing, healthcare, and finance. A 64-bit variant was introduced as operators adapted to wider deployment of 64-bit systems.
KIVARS is typically deployed as a multi-component implant consisting of a loader and an encrypted main backdoor. Configuration data, including mutexes and command-and-control information, is stored in encrypted form within the loader and passed to the main payload at runtime. In observed tradecraft, the loader establishes persistence by creating a Windows service and then executes the main backdoor directly in memory.
The malware provides remote access and surveillance functions suited to espionage operations. Documented capabilities include downloading and executing files, enumerating drives, taking screenshots, initiating keylogging, manipulating or hiding windows, triggering mouse and keyboard input, and uninstalling its own malware service. Its use of hidden-window behavior supports defense evasion by reducing visible signs of activity on the compromised host.
KIVARS forms part of a broader BlackTech toolset that has included BIFROSE, XBOW, PLEAD, TSCookie, Capgeld, and Waterbear. Within Shrouded Crossbow operations, KIVARS has been used alongside other BIFROST-derived backdoors, and multiple BlackTech malware families have been found on the same victims, indicating coordinated use in sustained intrusion activity. KIVARS is best characterized as an espionage backdoor used for covert access, host surveillance, and follow-on operator control on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE CANAL ... Tools ... Bifrose, Deuterbear, DRIGO, Flagpro, Gh0stTimes, KIVARS, PLEAD, Spiderpig, Waterbear, XBOW
Shrouded Crossbow employs three BIFROST-derived backdoors: BIFROSE, KIVARS, and XBOW.
Adversary Profile: HUAPI ... Malware: TSCOOKIE, KIVARS, CAPGELD, DBGPRINT
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Like PLEAD, Shrouded Crossbow uses spear-phishing emails with backdoor-laden attachments that utilize the RTLO technique and accompanied by decoy documents. | PLEAD’s installers are disguised as documents using the right-to-left-override (RTLO) technique to obfuscate the malware’s filename. They are mostly accompanied by decoy documents to further trick users.
the main backdoor that will be loaded into the loader’s memory and executed after decryption.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
PLEAD also uses the document-targeting exfiltration tool DRIGO, which mainly searches the infected machine for documents.
84 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware that conceals activity by hiding active windows.
Listed as a tool used by the BRONZE CANAL threat profile.
A Windows implant/loader used by BlackTech: dropped alongside an encrypted payload, persisted via a Windows service, and executes the main payload in-memory.
Backdoor malware that can uninstall malware from infected hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.