BITTER
MITRE ATT&CK: G1002 View on attack.mitre.org
Aliases: T-APT-17, Bitter, APT-C-08, Orange Yali, TA397, BITTER
- First seen
- 2013-01-01 00:00:00
- Origin
- IN
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- nation-state
- Related IoCs
- 32 (32 malicious)
- Last IoC activity
- 2026-09-03 04:01:20
- Profile updated
- 2026-07-07 11:48:12
Targeted industries: government-and-public-sector energy-and-utilities manufacturing
Targeted regions: country_code:pk country_code:cn country_code:bd country_code:sa
Context
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.
Recent IoC activity
32 malicious indicators in Maltiverse are attributed to BITTER (G1002). The 20 most recently updated:
Detection coverage
- 1 YARA rules
- 231 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
- Tool (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Malicious File (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Encrypted Channel (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Upload Malware (attack-pattern)
- Dynamic Data Exchange (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Domains (attack-pattern)
- Scheduled Task (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Phishing (attack-pattern)
- ZxxZ (malware)
Reports & references
- pwc.com — Yir Cyber Threats Report Download (report)
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- mp.weixin.qq.com — 8J Rha7Gdmxy1 X8Alj8Zg (report)
- bitdefender.com — Bitdefender Pr Whitepaper Bitterapt Creat4571 En En Genericuse (report)
- proofpoint.com — Hidden Plain Sight Ta397S New Attack Chain Delivers Espionage Rats (report)
- MITRE ATT&CK — G1002 (report)
- Cisco Talos — Bitter Apt Adds Bangladesh To Their (report)
- forcepoint.com — Bitter Targeted Attack Against Pakistan (report)