Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BITTER

Also known as: T-APT-17, Offshore APT organization from South Asia, Asia, Bitter, APT-C-08, Orange Yali, TA397, Bitter APT, Shell Crew, WebMasters, KungFu Kittens, energy, telecommunications, Hazy Tiger, 2025, tracked as, ZxxZ downloader, Cranberry, Pakistan, Sandworm Team, Operation Cleaver, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations

Description

BITTER is believed to be an offshore APT group operating from South Asia, with documented activity dating back to 2013. The actors employ a mix of well‑known and zero‑day vulnerabilities in Microsoft Office (CVE-2012-0158, CVE-2017-11882, CVE-2018-0798/0802) as well as recent Windows kernel exploits (CVE-2021-1732, CVE-2021-28310) and the mmc.exe bug CVE-2024-43572 to gain initial footholds via spear‑phishing attachments. After compromise, they download further payloads from HTTP hosting servers or use DNS-based C&C, deploying RATs such as Bitter‑RAT, ArtraDownloader, SlideRAT and AndroRAT for lateral movement and data exfiltration. The group also leverages PowerShell scripts to create scheduled tasks for persistence and to stage second‑stage payloads. They encode system identifiers in outbound C2 traffic to obfuscate telemetry and can masquerade malware as legitimate Windows services or security updates. Their operational tempo appears rapid, with frequent use of phishing campaigns tailored to high‑value officials across a wide array of countries, including Pakistan, China, Saudi Arabia and the United States. While the exact motivations remain ambiguous beyond espionage, BITTER’s consistent targeting of critical infrastructure sectors signals an intent to gather strategic information that could be leveraged for geopolitical influence or future operational advantage.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Healthcare
Energy
Education
Manufacturing
Media
Non profit
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Aerospace
Retail
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Food agriculture
Construction
Utilities

Targeted Countries / Regions

SA
CN
US
PK
RU
IR
JP
TW
VN
IN
IL
KR
GB
AU
AE
UA
SG
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 hours ago

Executive Summary

BITTER is a South‑Asian espionage adversary active since at least 2013, focused on government, defense and critical infrastructure targets across the globe. The group primarily uses spear‑phishing with malicious Office documents exploiting legacy CVEs and recent zero‑days, then deploys custom RATs via HTTP download servers leveraging DNS‑based C&C channels and scheduled tasks for persistence. Their operations reveal a sophisticated ability to pivot across multiple sectors—including energy, finance, telecommunications, and healthcare—while maintaining a highly adaptable attack lifecycle.

Goals & Targeting

BITTER’s overarching objective is long‑term intelligence gathering from political, economic and technological adversaries. By focusing on high‑profile organizations in government, defense, energy, finance and telecommunications, they aim to harvest policy documents, infrastructure schematics, and proprietary data that can inform state-level strategy or future cyber operations. The group adjusts its tactics based on target vulnerability posture—favoring zero‑days and legacy exploits when available—to ensure efficient infiltration while minimizing detection.

Enhanced Description

Key Capabilities

  • Spear‑phishing with malicious Office attachments
  • Exploitation of Microsoft Office CVEs (CVE-2012-0158, CVE-2017-11882, CVE-2018-0798/0802)
  • Use of Windows kernel zero‑days (CVE-2021-1732, CVE-2021-28310) and mmc.exe exploit (CVE-2024-43572)
  • Download of additional malware via HTTP hosting servers
  • DNS‑based command & control channels
  • Deployment of RATs such as Bitter‑RAT, ArtraDownloader, SlideRAT, AndroRAT
  • Persistence through PowerShell‑created scheduled tasks
  • Encoding machine identifiers in outbound C2 traffic
  • Use of RAR archives containing MSC files to trigger mmc.exe exploitation
  • Masquerading malware as legitimate Windows services or security updates

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Privilege Escalation

ATT&CK Techniques

T1053.005
T1068
T1105
T1071.004
T1021
T1203
T1059.003
T1566.001
T1583
T1027.013
T1559.002
T1204.002
T1608.001
T1583.001
T1036
T1568
T1559
T1027
T1573
T1203
T1095
T1071.001
T1105

Software / Tooling

ArtraDownloader
Bitter‑RAT
SlideRAT
AndroRAT
ZxxZ Downloader

Campaigns & Victims

Known campaigns typically begin with a spear‑phishing email sent to high‑profile insiders or contractors, embedding malicious Office documents that trigger known CVEs. Once the victim opens the attachment, an initial payload extracts further downloaders from HTTP servers and establishes DNS‑based command channels. The group demonstrates operational agility—adding new RATs such as SlideRAT or AndroRAT mid‑campaign—and often escalates privileges via local exploitation (CVE-2021-1732) before using PowerShell to create scheduled tasks that maintain persistence and allow for delayed activation of secondary components. Victim profiles span government agencies, defense contractors, energy utilities, financial institutions and telecommunications firms across more than thirty countries, illustrating a broad geographic appetite for strategic data.

IOC Patterns

  • CVE-based exploit references (e.g., CVE-2012-0158, CVE-2024-43572)
  • Malicious Office attachment files (RTF, XLSX) used in spear‑phishing
  • HTTP(S) URLs hosting downloader or RAT binaries
  • DNS domain names used for command & control communication
  • POST traffic containing user/hostname identifiers
  • RAR archive containing MSC file to trigger mmc.exe exploitation
  • PowerShell commands that create scheduled tasks
  • Scheduled task entries with unique identifiers

Recommended Actions

  • Patch all Microsoft Office applications against CVE-2012-0158, CVE-2017-11882, CVE-2018-0798/0802 and apply the latest security updates to address other relevant vulnerabilities.
  • Apply Windows kernel patches that remediate CVE-2021-1732, Desktop Manager CVE-2021-28310, and mmc.exe vulnerability CVE-2024-43572.
  • Implement advanced email filtering rules to block attachments from high‑rank officials with attachment extensions typical of malicious Office documents.
  • Block or quarantine known domains and IPs associated with Bitter downloaders and RATs (e.g., TEMP.Veles, princecleanit.com).
  • Monitor DNS traffic for anomalous queries that match known C&C patterns; set up alerts for new domain registrations linked to BITTER activity.
  • Deploy Endpoint Detection & Response solutions capable of detecting scheduled task creation via PowerShell, suspicious mmc.exe executions, and RAR archives with MSC files.
  • Enforce least privilege and restrict local privilege escalation points; regularly audit system permissions.
  • Conduct user awareness training focusing on spear‑phishing tactics and the dangers of enabling macros or opening unexpected attachments.

Suggested Tags

SpearPhishingAttachments
OfficeExploit
ZeroDayExploitation
RemoteAccessTrojan
CommandAndControl_DNS
Target-GlobalGovernment
Target-IndianSubcontinent
CriticalInfrastructure
ScheduledTasks
CVE_Exploit
mmc_Exploits
PowerShell
RAR_Archive
GrimResource

Confidence Assessment

The data available for BITTER is of moderate confidence: multiple independent sources concur on the group's use of spear‑phishing with Office attachments and reliance on known CVEs, indicating well‑documented operational patterns. However, attribution details (exact threat actor identity) remain uncertain due to overlapping aliases and limited direct evidence linking all observed behaviors to a single entity. Gaps exist in precise timing of attacks, full toolchain inventory, and the extent of use of zero‑day exploits beyond CVE-2024-43572.

ATT&CK Techniques

Command & Control
7 techniques
Execution
8 techniques
Lateral Movement
1 technique
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 4 IPv4 Address 2 Domain 10 SHA-256 Hash 1 URL 3

References

  1. Forcepoint BITTER Pakistan Oct 2016 — Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.
  2. Cisco Talos Bitter Bangladesh May 2022 — Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.
  3. attack.mitre.org — Cited by web research for: Sandworm Team
  4. attack.mitre.org — Cited by web research for: T1583
  5. www.proofpoint.com — Cited by web research for: PowerShell
  6. blog.talosintelligence.com — Cited by web research for: Maldoc
  7. apt.etda.or.th — Cited by web research for: CVE-2017-12824
  8. https://www.fortiguard.com/threat-actor/6256/bitter — Cited by AI analysis.
  9. https://ti.qianxin.com/blog/articles/bitter-uses-diverse-means-to-deliver-new-backdoor-components-en/ — Cited by AI analysis.
  10. https://nsfocusglobal.com/bitter-apt-targets-chinese-government-agency/ — Cited by AI analysis.
  11. https://attack.mitre.org/ — Cited by AI analysis.
  12. https://www.cisa.gov/news-events/bulletins/sb25-321 — Cited by AI analysis.

Intel Summary

30

Techniques

52

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

APT
espionage
government
energy sector
SpearPhishingAttachments
OfficeExploit
ZeroDayExploitation
RemoteAccessTrojan
CommandAndControl_DNS
Target-GlobalGovernment
Target-IndianSubcontinent
CriticalInfrastructure
ScheduledTasks
CVE_Exploit
mmc_Exploits
PowerShell
RAR_Archive
GrimResource

Details

MITRE ID
G1002
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--7f848c02-4d1e-4808-a4ae-4670681370a9
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.