All actors

BITTER

Also reported as T-APT-17, Bitter, TA397, HAZY TIGER, APT-C-08 and 1 other name. Linked to India by two sources.

Reports
28
Last reported
Known CVEs
18
Techniques in ATT&CK
17
Origin
India
ID
G1002
Merge evidence
11 alias matches

Reports per quarter

  1. 2016 Q4: 1 report
  2. 2017 Q1: no reports
  3. 2017 Q2: no reports
  4. 2017 Q3: no reports
  5. 2017 Q4: no reports
  6. 2018 Q1: no reports
  7. 2018 Q2: no reports
  8. 2018 Q3: no reports
  9. 2018 Q4: no reports
  10. 2019 Q1: no reports
  11. 2019 Q2: no reports
  12. 2019 Q3: 4 reports
  13. 2019 Q4: no reports
  14. 2020 Q1: no reports
  15. 2020 Q2: 2 reports
  16. 2020 Q3: no reports
  17. 2020 Q4: 1 report
  18. 2021 Q1: 1 report
  19. 2021 Q2: 1 report
  20. 2021 Q3: no reports
  21. 2021 Q4: 1 report
  22. 2022 Q1: no reports
  23. 2022 Q2: 3 reports
  24. 2022 Q3: 4 reports
  25. 2022 Q4: no reports
  26. 2023 Q1: no reports
  27. 2023 Q2: no reports
  28. 2023 Q3: no reports
  29. 2023 Q4: no reports
  30. 2024 Q1: no reports
  31. 2024 Q2: no reports
  32. 2024 Q3: no reports
  33. 2024 Q4: 2 reports
  34. 2025 Q1: no reports
  35. 2025 Q2: 3 reports
  36. 2025 Q3: no reports
  37. 2025 Q4: no reports
  38. 2026 Q1: no reports
  39. 2026 Q2: 5 reports
Dated reports, 2016 Q4 to 2026 Q2.

Techniques in ATT&CK

Listed by ATT&CK

Show all 17 techniques Show fewer

No report from the last two years names a technique ID.

CVEs named in reports

Show all 18 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

Show all 28 reports Show fewer
  1. Bitter APT Group Using “Dracarys” Android Spyware

    date in the title fromORKL

  2. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  3. 蔓灵花APT组织利用恶意CHM文档针对国内研究机构的攻击活动分析

    date in the CCS '25 data 奇安信 fromORKLCCS '25 data

  4. 200407-MWB-COVID-White-Paper_Final

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  5. BITTER APT_ Not So Sweet

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  6. Bitter_APT_Malware_analysis

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  7. APT-C-09

    date in the CCS '25 data QiAnXin fromORKLCCS '25 data

  8. BITTER: A Targeted attack against Pakistan

    date in the CCS '25 data Forcepoint fromORKLCCS '25 data

Newest first. Details opens the report in Explore.