AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
BITTER
Aliases: T-APT-17
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.
Open interactive actor investigation
ATT&CK techniques
Ingress Tool TransferT1071.001
Web ProtocolsT1588.002
ToolT1568
Dynamic ResolutionT1566.001
Spearphishing AttachmentT1204.002
Malicious FileT1027.013
Encrypted/Encoded FileT1573
Encrypted ChannelT1068
Exploitation for Privilege EscalationT1036.004
Masquerade Task or ServiceT1608.001
Upload MalwareT1559.002
Dynamic Data ExchangeT1203
Exploitation for Client ExecutionT1583.001
DomainsT1053.005
Scheduled TaskT1095
Non-Application Layer Protocol
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Vulnerability Research & Exploit Development · explicit-idModule 7 — Privilege, lateral movement, and controlled impact
Red Team & Offensive Security · explicit-nameModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · explicit-nameControlled dynamic behavior and differential observation
Malware Analysis & Reverse Engineering · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameModule 1 — Foundations: What CTI Is
Cyber Threat Intelligence (CTI) · explicit-nameModule 4 — Collection Sources
Cyber Threat Intelligence (CTI) · explicit-nameModule 5 — Analysis Techniques Tradecraft
Cyber Threat Intelligence (CTI) · explicit-nameModule 7 — Intelligence Products Sharing
Cyber Threat Intelligence (CTI) · explicit-nameModule 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · explicit-nameModule 2 — Reconnaissance and attack-surface mapping
Red Team & Offensive Security · explicit-nameModule 6 — Active Directory and identity attack paths
Red Team & Offensive Security · explicit-name