BITTER
Aliases: T-APT-17
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.
Open interactive actor investigation
ATT&CK techniques
T1105
Ingress Tool TransferT1071.001
Web ProtocolsT1588.002
ToolT1568
Dynamic ResolutionT1566.001
Spearphishing AttachmentT1204.002
Malicious FileT1027.013
Encrypted/Encoded FileT1573
Encrypted ChannelT1068
Exploitation for Privilege EscalationT1036.004
Masquerade Task or ServiceT1608.001
Upload MalwareT1559.002
Dynamic Data ExchangeT1203
Exploitation for Client ExecutionT1583.001
DomainsT1053.005
Scheduled TaskT1095
Non-Application Layer Protocol
Ingress Tool TransferT1071.001
Web ProtocolsT1588.002
ToolT1568
Dynamic ResolutionT1566.001
Spearphishing AttachmentT1204.002
Malicious FileT1027.013
Encrypted/Encoded FileT1573
Encrypted ChannelT1068
Exploitation for Privilege EscalationT1036.004
Masquerade Task or ServiceT1608.001
Upload MalwareT1559.002
Dynamic Data ExchangeT1203
Exploitation for Client ExecutionT1583.001
DomainsT1053.005
Scheduled TaskT1095
Non-Application Layer Protocol