Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
BITTER
ID: a31ceefc81a057c851ee4e37cc8cb08f06496
Cybercrime
State-Sponsored
Threat types: Intrusion, Espionage, Malware
Progress: 38%
Completeness: 33%
Freshness: 50%
Operation zone: UNKNOWN
Aliases
Limited alias preview
| T-APT-17 | — | — | — |
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia. Ref: https://attack.mitre.org/groups/G1002/
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1027.013 | Encrypted/Encoded File | TA0005 |
|
| T1036.004 | Masquerade Task or Service | TA0005 |
|
| T1053.005 | Scheduled Task | TA0002 TA0003 TA0004 |
|
| T1071.001 | Web Protocols | TA0011 |
|
| T1204.002 | Malicious File | TA0002 |
|
| T1559.002 | Dynamic Data Exchange | TA0002 |
|
| T1566.001 | Spearphishing Attachment | TA0001 |
|
| T1583.001 | Domains | TA0042 |
|
| T1588.002 | Tool | TA0042 |
|
| T1608.001 | Upload Malware | TA0042 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.