ATT&CKReferencesForcepoint BITTER Pakistan Oct 2016

Forcepoint BITTER Pakistan Oct 2016

Dela Paz, R. (2016, October 21). BITTER: a targeted attack against Pakistan. Retrieved June 1, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupBITTER

BITTER has used a RAR SFX dropper to deliver malware.

T1071.001
Web Protocols
GroupBITTER

BITTER has used HTTP POST requests for C2.

T1095
Non-Application Layer Protocol
GroupBITTER

BITTER has used TCP for C2 communications.

T1105
Ingress Tool Transfer
GroupBITTER

BITTER has downloaded additional malware and tools onto a compromised host.

T1203
Exploitation for Client Execution
GroupBITTER

BITTER has exploited Microsoft Office vulnerabilities CVE-2012-0158, CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802.

T1204.002
Malicious File
GroupBITTER

BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing.

T1566.001
Spearphishing Attachment
GroupBITTER

BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet.

T1568
Dynamic Resolution
GroupBITTER

BITTER has used DDNS for C2 communications.

T1573
Encrypted Channel
GroupBITTER

BITTER has encrypted their C2 communications.

T1583.001
Domains
GroupBITTER

BITTER has registered a variety of domains to host malicious payloads and for C2.

T1588.002
Tool
GroupBITTER

BITTER has obtained tools such as PuTTY for use in their operations.

T1608.001
Upload Malware
GroupBITTER

BITTER has registered domains to stage payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.