A compromised library website on a Taiwanese academic network was used to host the BiFrost backdoor after attackers allegedly exploited Apache Tomcat's Ghostcat vulnerability, CVE-2020-1938. TeamT5 said the exposed Tomcat 7.0.73 server had the AJP service on port 8009 enabled, allowing the attackers to upload a Linux BiFrost payload disguised as a PNG file named md.png and turn the site into a malware distribution point. The malware was identified as an ELF executable, communicated with relay IP 107.191.61.247, and used a modified RC4 algorithm for encrypted traffic.
TeamT5 attributed the activity to the China-linked HUAPI group, also tracked as PLEAD, which has a history of targeting Taiwan and other countries. The underlying Ghostcat flaw affects Tomcat's AJP connector and can allow arbitrary file reads, JSP processing, and, in some upload scenarios, remote code execution when the AJP port is reachable by untrusted users. Apache has recommended upgrading to Tomcat 9.0.31, 8.5.51, 7.0.100, or later, along with hardened AJP defaults, to prevent malicious file uploads and remote control of exposed servers.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2020-1938 was updated. The record continued to document Apache's mitigation guidance and affected Tomcat versions.
CVE-2020-1938 was published describing an Apache Tomcat AJP connector vulnerability that could allow arbitrary file reads and, in some cases, remote code execution. The issue affected multiple Tomcat 7, 8.5, and 9 versions where AJP was enabled by default and exposed to untrusted users.
A malware sample later identified as a Linux BiFrost backdoor was uploaded to VirusTotal with MD5 hash 8fd3925dadf37bebcc8844214f2bcd18. At the time of upload, only six antivirus engines detected it.
TeamT5 reported that a library website on a Taiwanese academic network had been compromised and used to host a Linux BiFrost backdoor disguised as a PNG file, likely after exploitation of Ghostcat on an exposed Tomcat 7.0.73 server with AJP port 8009 enabled. The firm attributed the malware to the China-linked HUAPI threat actor and identified relay IP 107.191.61.247 and modified RC4-encrypted communications as key technical details.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.