news.mlab.sh
Threat intelligence
Threat actor

Bitter

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
[South Asia]
First seen
2013-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Energy, Engineering, Government
TLP
WHITE

(Forcepoint) Forcepoint Security Labs recently encountered a strain of attacks that appear to target Pakistani nationals. We named the attack “BITTER” based on the network communication header used by the latest variant of remote access tool (RAT) used. Our investigation indicates that the campaign has existed since at least November 2013 but has remained active until today.

Also known as

BITTERG1002T-APT-17TA397

Vulnerabilities exploited

Tooling and malware

ZxxZ

MITRE ATT&CK techniques

T1095 Non-Application Layer ProtocolT1105 Ingress Tool TransferT1568 Dynamic ResolutionT1573 Encrypted ChannelT1203 Exploitation for Client ExecutionT1068 Exploitation for Privilege Escalation

Coverage 2