The Bitter espionage group, also tracked as TA397 and APT-Q-37, has conducted sustained targeting across South Asia and neighboring regions, hitting government, military, energy, engineering, and other sensitive organizations in countries including Bangladesh, Pakistan, Saudi Arabia, and China. Researchers linked the activity through overlapping command-and-control infrastructure, recurring phishing lures, and repeated use of malicious Office documents, MSI installers, SFX archives, and compromised legitimate websites. In one campaign against Bangladeshi law-enforcement officials, spear-phishing emails delivered weaponized RTF and Excel files that exploited known Microsoft Office flaws to install the ZxxZ trojan, while earlier operations against Pakistan and Saudi Arabia used ArtraDownloader, including samples exploiting CVE-2017-11882 via Microsoft Equation Editor.

TTPs, infrastructure, and targeting history in one profile.
26 events from the most recent confirmed update back to the earliest known activity.
ThreatRay documented a newly identified MuuyDownloader variant seen in 2025 that Base64-encodes system information before transmitting it to command-and-control infrastructure.
ThreatRay said a BDarkRAT variant discovered by Proofpoint in early 2025 retained newer capabilities but reverted to hex-encoded C2 addresses.
QiAnXin reported that Bitter ultimately distributed a new trojan named MiyaRat in September 2024 via an MSI installer, after earlier 2024 attempts with other tooling were reportedly ineffective.
QiAnXin said Bitter used a steganography plugin in July 2024 that had previously been used in 2018, indicating reuse of older tradecraft.
QiAnXin reported that Bitter experimented in June 2024 with loading the Havoc framework through PowerShell before later changing tooling again.
ThreatRay noted that WmRAT, first observed in 2022, was also seen again in Bitter campaigns during 2024.
ThreatRay reported that a newer BDarkRAT variant seen in 2024 added screen capture and PowerShell command execution capabilities and used AES-256-CBC to encrypt its C2 address.
ThreatRay said WmRAT, a C++ RAT supporting screenshot capture, file theft, and PowerShell command execution, was first observed in 2022.
ThreatRay reported that AlmondRAT, a .NET RAT used by Bitter, was discovered in 2022 and supports system-information collection, file transfer, and shell command execution.
Cisco Talos said Bitter's campaign targeting Bangladeshi government organizations commenced in August 2021 and used spear-phishing emails with weaponized Office documents.
ThreatRay said MuuyDownloader replaced ArtraDownloader in 2021 as Bitter's primary downloader, marking a shift in the group's main delivery tooling.
Unit 42 noted that the file "article_amy.doc," hosted on almasoodgroup[.]com/js/cwqj and communicating with thepandaservices.nsiagenthoster[.]net, was uploaded to VirusTotal on January 2, 2019.
ThreatRay reported that BDarkRAT, a .NET remote access trojan used by Bitter, was first discovered in 2019 and remained in use through 2025.
On December 17 and 18, 2018, an ArtraDownloader Variant 1 payload was downloaded from fst.gov[.]pk/images/winsvc after a user accessed the exploit document "cocktail and the dinner in the last week of dec.doc."
Beginning on November 6, 2018, rmmun.org[.]pk/svch hosted two ArtraDownloader files that communicated with info.viewworld71[.]com or hewle.kielsoservice[.]net.
Beginning on September 12, 2018, files including "Internet Data Traffic Report – August 2018.docx" and "PAF Webmail Security Report.doc.exe" were hosted at wforc[.]pk/js/ and used in a presumed spear-phish targeting a Saudi organization employee.
Unit 42 observed ArtraDownloader campaigns targeting organizations in Pakistan and Saudi Arabia between mid-September 2018 and January 2019 using malicious documents and executables hosted on likely compromised Pakistani websites.
Unit 42 first observed ArtraDownloader querying zmwardrobe[.]com in November 2017, with that activity continuing through February 2018.
Unit 42 said that in November 2017 it reported malicious documents downloaded from zmwardrobe[.]com that executed the MY24 payload, later noting infrastructure overlap with ArtraDownloader activity.
ThreatRay said ArtraDownloader, Bitter's first known malware family, and the WSCSPL backdoor were first seen in 2016, beginning Bitter's documented progression from simple downloaders to broader malware tooling.
Unit 42 reported that the earliest identified ArtraDownloader sample carried a compile timestamp from February 2015, marking the earliest dated sample they found for the malware family.
Cisco Talos said the earliest attacks distributing the mobile version of BitterRAT date back to September 2014, establishing an early known point in Bitter's activity history.
Forcepoint Security Labs described and named a targeted cyber-espionage campaign as BITTER, saying it had been active since at least November 2013 and primarily targeted Pakistani nationals, including individuals in Pakistani government branches. The report said the campaign mainly used spear-phishing with CVE-2012-0158 Office exploits and custom RAT malware.
ThreatRay assessed with high confidence that Bitter, also tracked as TA397, is likely a state-backed espionage actor operating in the interests of the Indian government.
Cisco Talos reported that Bitter expanded an ongoing campaign to target Bangladeshi government organizations, specifically high-ranking officers in the Rapid Action Battalion Unit, and attributed the activity to Bitter with moderate confidence.
QiAnXin reported a targeted intrusion campaign against domestic Chinese enterprises and attributed it with high confidence to the BITTER APT group based on malware and infrastructure overlaps.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 152 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
threatray.com
Open sourceti.qianxin.com
Open sourcethehackernews.com
Open sourceunit42.paloaltonetworks.com
Open sourceti.qianxin.com
Open sourceforcepoint.com
Open sourceapt.360.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.