Bitter is a suspected India-nexus cyberespionage threat actor tracked by some vendors as TAG-179, Mysterious Elephant, and APT-C-08. The group has been associated with espionage activity targeting Pakistani government and law-enforcement entities, including police organizations in Balochistan, Khyber Pakhtunkhwa, Islamabad, and Punjab. In the referenced activity cluster, the actor was linked with lower confidence to intrusions against Pakistani law-enforcement infrastructure between January and April 2026, overlapping with operations that used Remcos and lure material themed around the repatriation of undocumented or illegal foreigners in Pakistan, including Afghan nationals. The actor’s tradecraft is consistent with targeted intrusion and intelligence collection. Reported behavior includes the use of themed decoy documents for initial access, remote-access malware for post-compromise control, and command-and-control infrastructure overlapping with activity previously associated with Bitter and Mysterious Elephant. The targeting indicates an interest in sensitive police and administrative data, including records relevant to internal security, identity management, and regional unrest in Balochistan. Based on the available evidence, the group is best characterized as an espionage actor rather than a financially motivated or disruptive operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected India-nexus cyberespionage activity targeting Pakistani law enforcement, including Balochistan Police, using a Remcos tooling cluster and lures themed around repatriation of Afghan nationals.
Conducted India-linked cyber espionage intrusions against Pakistani law enforcement, specifically overlapping with activity targeting the Balochistan Police.
India-nexus cyberespionage activity targeting Pakistani law enforcement, especially Balochistan Police, using Remcos infrastructure and law-enforcement-themed lure documents.
Suspected India-nexus cyberespionage activity targeting Pakistani law enforcement, especially Balochistan Police, using Remcos infrastructure and law-enforcement-themed lure documents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.