MuuyDownloader, also known as ZxxZ, is a Windows downloader used by the Bitter espionage group, also tracked as TA397. It emerged in 2021 as Bitter’s primary successor to ArtraDownloader and reflects the group’s progression from simple first-stage malware toward more capable access tooling. MuuyDownloader is associated with targeted cyber-espionage operations against government, diplomatic, and defense-related organizations, particularly in campaigns aligned with Bitter’s long-running intelligence collection activity.
MuuyDownloader is implemented in C++ and functions as an initial-stage payload delivery component. It gathers basic host reconnaissance data, including common system-identification details, transmits that information to command-and-control infrastructure, receives a follow-on payload designation, reconstructs a portable executable payload, and executes it on the compromised host. Reporting also characterizes it as enabling remote code execution of payloads supplied by its server. Multiple variants have been documented, with changes over time in string decryption routines, command-and-control data separators, payload formatting, and execution methods. A variant observed in 2025 additionally Base64-encoded collected system information before transmission.
The malware has been observed delivering additional Bitter tooling, including a keylogger, BDarkRAT, and AlmondRAT, making it a key staging component in the actor’s intrusion chain. Its role is primarily to establish foothold utility and hand off execution to more capable surveillance or remote-access payloads rather than to provide extensive operator functionality itself. Consistent with broader Bitter development patterns, MuuyDownloader shares recurring implementation traits seen across the group’s malware families, especially around system-information collection and lightweight obfuscation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2021, Bitter switched from ArtraDownloader to a new downloader called MuuyDownloader (also known as ZxxZ downloader).
7 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojan/downloader that enables remote code execution by running payloads received from a remote server.
Downloader/loader used in Bitter/TA397 campaigns as part of an evolving toolset supporting targeted intrusion activity.
A C++ downloader similar to ArtraDownloader that gathers system information, sends it to C2 in encrypted form, receives a payload name, reconstructs and writes the downloaded PE payload, and executes the next stage. Variants differ in string obfuscation, payload formatting, and execution method.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.