Bitter is a suspected India-nexus cyber espionage threat actor tracked by some vendors as TAG-179, Mysterious Elephant, and APT-C-08. The group has been associated with espionage activity targeting Pakistani law enforcement organizations, including Balochistan Police, as part of broader intelligence collection aligned with India-Pakistan strategic rivalry. Reported targeting has included police environments containing biometric records, criminal case files, personnel information, hotel and tenant registration data, and citizen complaint information. In the referenced activity, the actor was linked with a Remcos-based intrusion cluster and assessed with lower confidence to overlap with infrastructure, tooling, and tradecraft attributed by other researchers to Bitter and Mysterious Elephant. Observed lures included documents themed around the repatriation of undocumented or illegal foreigners in Pakistan, indicating use of topical social engineering tailored to Pakistani administrative and security workflows. The actor is therefore associated with targeted intrusion activity for intelligence collection rather than financially motivated operations. High-confidence reporting in this context supports Bitter's role in initial compromise and post-compromise espionage against Pakistani government and law-enforcement targets, including use of commodity remote-access malware for persistence, remote control, and likely data theft. The available information here supports an India nexus and espionage motivation, but does not establish ransomware or extortion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected India-nexus cyberespionage activity targeting Pakistani law enforcement, including Balochistan Police, using a Remcos tooling cluster and lures themed around repatriation of Afghan nationals.
Suspected India-nexus espionage actor linked to a Remcos-based intrusion cluster targeting Pakistani law enforcement bodies, including Balochistan Police.
Conducted India-linked cyber espionage intrusions against Pakistani law enforcement, specifically overlapping with activity targeting the Balochistan Police.
India-nexus cyberespionage activity targeting Pakistani law enforcement, especially Balochistan Police, using Remcos infrastructure and law-enforcement-themed lure documents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.