BITTER

MITRE ATT&CK: G1002 View on attack.mitre.org

Aliases: T-APT-17, Bitter, APT-C-08, Orange Yali, TA397, BITTER

First seen
2013-01-01 00:00:00
Origin
IN
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Related IoCs
32 (32 malicious)
Last IoC activity
2026-09-03 04:01:20
Profile updated
2026-07-07 11:48:12

Targeted industries: government-and-public-sector energy-and-utilities manufacturing

Targeted regions: country_code:pk country_code:cn country_code:bd country_code:sa

Context

BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.

Recent IoC activity

32 malicious indicators in Maltiverse are attributed to BITTER (G1002). The 20 most recently updated:

Detection coverage

  • 1 YARA rules
  • 231 Sigma rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Web Protocols (attack-pattern)
  • Tool (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious File (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Encrypted Channel (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Upload Malware (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Domains (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Phishing (attack-pattern)
  • ZxxZ (malware)

Reports & references

  • pwc.com — Yir Cyber Threats Report Download (report)
  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • mp.weixin.qq.com — 8J Rha7Gdmxy1 X8Alj8Zg (report)
  • bitdefender.com — Bitdefender Pr Whitepaper Bitterapt Creat4571 En En Genericuse (report)
  • proofpoint.com — Hidden Plain Sight Ta397S New Attack Chain Delivers Espionage Rats (report)
  • MITRE ATT&CK — G1002 (report)
  • Cisco Talos — Bitter Apt Adds Bangladesh To Their (report)
  • forcepoint.com — Bitter Targeted Attack Against Pakistan (report)

External references