Bitter is a suspected India-nexus cyberespionage threat actor associated with targeted intrusions in South Asia. The cluster has been linked by multiple vendors under overlapping names including TAG-179, Mysterious Elephant, and APT-C-08. Attribution between these labels is not universally resolved, but reported overlaps in infrastructure, tooling, and tradecraft indicate they likely describe the same or closely related activity. The actor has been observed targeting Pakistani government and law-enforcement entities, including organizations connected to policing and internal security in Balochistan. Reported targeting themes indicate an intelligence-collection focus aligned with regional security interests and India-Pakistan geopolitical rivalry, including visibility into law-enforcement operations, internal security posture, and issues related to undocumented foreigners and Afghan nationals. Observed tradecraft includes spearphishing and lure documents tailored to Pakistani administrative and security topics, followed by deployment of commodity remote-access malware such as Remcos. The actor’s operations have been associated with command-and-control infrastructure and delivery chains overlapping with previously documented Bitter activity. Reported lures have impersonated official operational planning material and referenced coordination among police, identity-management, and intelligence bodies, reflecting a pattern of socially engineered content designed for government recipients. The cluster is assessed as an espionage actor rather than a financially motivated operator. Its known behavior is consistent with credential theft, persistent remote access, surveillance of victim environments, and collection of sensitive government and security-related information. Public reporting in this context ties TAG-179 to intrusions against Pakistani law-enforcement networks with lower confidence, while the overlap with Bitter and Mysterious Elephant strengthens the assessment that the activity belongs to a broader India-aligned espionage ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted India-linked cyber espionage intrusions against Pakistani law enforcement, specifically overlapping with activity targeting the Balochistan Police.
India-nexus cyberespionage activity targeting Pakistani law enforcement, especially Balochistan Police, using Remcos infrastructure and law-enforcement-themed lure documents.
Suspected India-nexus cyberespionage activity targeting Pakistani law enforcement, especially Balochistan Police, using Remcos infrastructure and law-enforcement-themed lure documents.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.