BITTER
[BITTER](https://attack.mitre.org/groups/G1002) is a suspected South Asian cyber espionage threat group that has been active since at least 2013. [BITTER](https://attack.mitre.org/groups/G1002) has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.(Citation: Cisco Talos Bitter Bangladesh May 2022)(Citation: Forcepoint BITTER Pakistan Oct 2016)
Properties
- stix_id
- intrusion-set--7f848c02-4d1e-4808-a4ae-4670681370a9
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (16)
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresse
Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands. DDE is a client-server protocol for one-time and/or continuous
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achie
Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a co
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversar
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to ope
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Schedu
Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The l
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple w
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a sp
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A to
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can in
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with exi
Software & Tools (1)
[ZxxZ](https://attack.mitre.org/software/S1013) is a trojan written in Visual C++ that has been used by [BITTER](https://attack.mitre.org/groups/G1002
Explore this actor's full graph with Ninja Signal