ATT&CKReferencesCisco Talos Bitter Bangladesh May 2022

Cisco Talos Bitter Bangladesh May 2022

Raghuprasad, C . (2022, May 11). Bitter APT adds Bangladesh to their targets. Retrieved June 1, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareZxxZ

ZxxZ can collect data from a compromised host.

T1012
Query Registry
MalwareZxxZ

ZxxZ can search the registry of a compromised host.

T1027.013
Encrypted/Encoded File
MalwareZxxZ

ZxxZ has been encoded to avoid detection from static analysis tools.

T1033
System Owner/User Discovery
MalwareZxxZ

ZxxZ can collect the username from a compromised host.

T1036.004
Masquerade Task or Service
GroupBITTER

BITTER has disguised malware as a Windows Security update service.

T1036.004
Masquerade Task or Service
MalwareZxxZ

ZxxZ has been disguised as a Windows security update service.

T1053.005
Scheduled Task
GroupBITTER

BITTER has used scheduled tasks for persistence and execution.

T1053.005
Scheduled Task
MalwareZxxZ

ZxxZ has used scheduled tasks for persistence and execution.

T1057
Process Discovery
MalwareZxxZ

ZxxZ has created a snapshot of running processes using `CreateToolhelp32Snapshot`.

T1071.001
Web Protocols
GroupBITTER

BITTER has used HTTP POST requests for C2.

T1082
System Information Discovery
MalwareZxxZ

ZxxZ has collected the host name and operating system product name from a compromised machine.

T1105
Ingress Tool Transfer
GroupBITTER

BITTER has downloaded additional malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
MalwareZxxZ

ZxxZ can download and execute additional files.

T1106
Native API
MalwareZxxZ

ZxxZ has used API functions such as `Process32First`, `Process32Next`, and `ShellExecuteA`.

T1140
Deobfuscate/Decode Files or Information
MalwareZxxZ

ZxxZ has used a XOR key to decrypt strings.

T1203
Exploitation for Client Execution
GroupBITTER

BITTER has exploited Microsoft Office vulnerabilities CVE-2012-0158, CVE-2017-11882, CVE-2018-0798, and CVE-2018-0802.

T1204.002
Malicious File
MalwareZxxZ

ZxxZ has relied on victims to open a malicious attachment delivered via email.

T1204.002
Malicious File
GroupBITTER

BITTER has attempted to lure victims into opening malicious attachments delivered via spearphishing.

T1518.001
Security Software Discovery
MalwareZxxZ

ZxxZ can search a compromised host to determine if it is running Windows Defender or Kasperky antivirus.

T1559.002
Dynamic Data Exchange
GroupBITTER

BITTER has executed OLE objects using Microsoft Equation Editor to download and run malicious payloads.

T1566.001
Spearphishing Attachment
MalwareZxxZ

ZxxZ has been distributed via spearphishing emails, usually containing a malicious RTF or Excel attachment.

T1566.001
Spearphishing Attachment
GroupBITTER

BITTER has sent spearphishing emails with a malicious RTF document or Excel spreadsheet.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.