Bitter
BITTER is a threat actor also referenced in the provided content as APT-C-08, Bitter APT, Hazy Tiger, Manlinghua, TA397, and T-APT-17. The content associates BITTER with spearphishing-based initial access, including emails carrying malicious RTF documents or Excel spreadsheets, and attempts to lure victims into opening malicious attachments. It also links BITTER to UDL-file-based spearphishing attachment activity. For persistence and execution, BITTER has used Windows Scheduled Tasks. For malware delivery, the group has used a RAR SFX dropper. For command and control, the content states BITTER has used HTTP POST requests. The content also notes BITTER has obtained and used PuTTY in operations. Additional ATT&CK-style annotations in the source associate BITTER with Exploit Public-Facing Application, Upload Malware, Upload Tool, Exploitation for Privilege Escalation, Malicious File Execution, and Msiexec-related stealth activity, but the content does not provide campaign-specific detail for those beyond the annotations.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
Associated vulnerabilities
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
...has exploited client software vulnerabilities for execution, such as Microsoft Word CVE-2012-0158...
...has exploited Office vulnerabilities such as CVE-2017-11882...
BITTER has exploited Microsoft Office vulnerabilities... CVE-2018-0798...
...has exploited Microsoft Office vulnerabilities... CVE-2018-0802.
BITTER has exploited CVE-2021-1732 for privilege escalation.
3 more CVEs tied to this actor tracked in Mallory.
Observables
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection annotations as a threat actor associated with exploitation for privilege escalation.
Conducting a spying campaign targeting journalists and opposition politicians in the Middle East, using spear-phishing, fake login pages, malicious Signal QR codes, and Android spyware including ProSpy and ToSpy. The group is also described as historically targeting military, energy, and government entities.
Referenced as a threat actor associated with exploitation for privilege escalation, specifically the use of Windows Potato-family privilege escalation tools.
Listed in the detection annotations as a threat actor associated with EFI volume mounting / installation-related behavior.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.