BITTER

G1002

Threat group.View on attack.mitre.org

About this group

BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

BITTER has used a RAR SFX dropper to deliver malware.

T1036.004
Masquerade Task or Service

BITTER has disguised malware as a Windows Security update service.

T1053.005
Scheduled Task

BITTER has used scheduled tasks for persistence and execution.

T1068
Exploitation for Privilege Escalation

BITTER has exploited CVE-2021-1732 for privilege escalation.

T1071.001
Web Protocols

BITTER has used HTTP POST requests for C2.

T1095
Non-Application Layer Protocol

BITTER has used TCP for C2 communications.

T1105
Ingress Tool Transfer

BITTER has downloaded additional malware and tools onto a compromised host.

T1203
Exploitation for Client Execution

BITTER has exploited Microsoft Office vulnerabilities CVE-2012-0158, CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802.

T1204.002
Malicious File

BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing.

T1559.002
Dynamic Data Exchange

BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads.

T1566.001
Spearphishing Attachment

BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet.

T1568
Dynamic Resolution

BITTER has used DDNS for C2 communications.

T1573
Encrypted Channel

BITTER has encrypted their C2 communications.

T1583.001
Domains

BITTER has registered a variety of domains to host malicious payloads and for C2.

T1588.002
Tool

BITTER has obtained tools such as PuTTY for use in their operations.

View all 16 procedure examples

Software1

Campaigns0

None recorded.

References2

  1. Cisco Talos Bitter Bangladesh May 2022 Open source
    Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.
  2. Forcepoint BITTER Pakistan Oct 2016 Open source
    Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.