BITTER
Also reported as T-APT-17, Bitter, TA397, HAZY TIGER, APT-C-08 and 1 other name. Linked to India by two sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-26411 KEV ransomware
Show all 18 CVEs Show fewer
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 28 reports Show fewer
-
Bitter APT Group Using “Dracarys” Android Spyware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bitter APT Group Using “Dracarys” Android Spyware
-
Whatever floats your Boat – Bitter APT continues to target Bangladesh
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Whatever floats your Boat – Bitter APT continues to target Bangladesh
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco Talos Intelligence Group - Comprehensive Threat Intelligence_ Bitter APT adds Bangladesh to their targets
-
Bitter APT Hackers Add Bangladesh to Their List of Targets in South Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bitter APT Hackers Add Bangladesh to Their List of Targets in South Asia
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild _ Securelist
-
Disclosure of Manling Flower Organization (APT-C-08) using Warzone RAT attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Disclosure of Manling Flower Organization (APT-C-08) using Warzone RAT attack
-
蔓灵花APT组织利用恶意CHM文档针对国内研究机构的攻击活动分析
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 蔓灵花APT组织利用恶意CHM文档针对国内研究机构的攻击活动分析
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BITTER APT_ Not So Sweet
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bitter_APT_Malware_analysis
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-09
-
Suspected BITTER APT Continues Targeting Government of China and Chinese Organizations _ Anomali
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Suspected BITTER APT Continues Targeting Government of China and Chinese Organizations _ Anomali
-
BITTER: A Targeted attack against Pakistan
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor BITTER: A Targeted attack against Pakistan
Newest first. Details opens the report in Explore.