Bitter is a suspected India-linked, state-backed cyber-espionage group assessed to operate in the interests of the Indian government. Also tracked as TA397, APT-C-08, T-APT-17, Bitter APT, Bitter APT Group, Bitter (G1002), Hazy Tiger, Manlinghua, and 蔓灵花, it has conducted sustained intelligence-collection operations since at least 2016. Bitter has targeted government, military and defense-related organizations, energy and power entities, nuclear-sector organizations, engineering organizations, and telecommunications personnel, principally in Pakistan and China, with additional confirmed targeting in Bangladesh, Saudi Arabia, and Turkey. Bitter commonly obtains initial access through spear-phishing using weaponized Microsoft Office, InPage, and other decoy documents, as well as malicious installers and executables. Campaigns have exploited known Office and InPage vulnerabilities and have also been associated with exploitation of the Windows elevation-of-privilege vulnerabilities CVE-2021-1732 and CVE-2021-28310. The group has used compromised legitimate websites and compromised email accounts for delivery and social-engineering operations. Its malware ecosystem includes ArtraDownloader, MuuyDownloader, WSCSPL, BDarkRAT, AlmondRAT, WmRAT, ORPCBackdoor, MiyaRAT, KiwiStealer, KugelBlitz, ZxxZ, and BitterRAT. These tools support host profiling, drive and directory enumeration, file collection and transfer, screenshot capture, command execution through command shells and PowerShell, remote file management, and data exfiltration. Bitter has deployed keylogging modules and has established persistence through Windows Run-registry entries, startup shortcuts, and secondary components. Its malware development shows recurring code and implementation patterns, including consistent collection of host identifiers and evolving string and command-and-control obfuscation. The group also uses hands-on-keyboard activity and has deployed the Havoc command-and-control framework in some operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
While analyzing the CVE-2021-1732 exploit originally discovered by the DBAPPSecurity Threat Intelligence Center and used by the BITTER APT group, we discovered another zero-day exploit we believe is linked to the same actor.
One of the files, Port Details.doc is an RTF document crafted to exploit the EQNEDT vulnerability CVE-2017-11882. ... This payload is an instance of ArtraDownloader variant 1 exploits CVE-2017-11882 (EQNEDT).
The campaign predominantly used the older, relatively popular Microsoft Office exploit, CVE-2012-0158, in order to download and execute a RAT binary from a website.
While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence.
While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence.
5 more CVEs tied to this actor tracked in Mallory.
230 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection's APT annotations.
BITTER is listed in the detection's ATT&CK annotations for T1068, Exploitation for Privilege Escalation.
Listed in the analytic's ATT&CK annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.