BITTER
Also known as: T-APT-17
Overview
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.
Naming & attribution
BITTER is tracked under 2 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here. Activity attributed since at least 2013.
| Name | First reported by |
|---|---|
| T-APT-17 | Raghuprasad, C |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- IndigoZebra China — 5 shared techniques (28% overlap)
- TA2541 — 9 shared techniques (26% overlap)
- Transparent Tribe Pakistan — 6 shared techniques (25% overlap)
- Elderwood China — 5 shared techniques (25% overlap)
- Metador — 5 shared techniques (25% overlap)
- Rancor — 5 shared techniques (25% overlap)
Regions
Germany
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1203
TTPs — 16 techniques across 6 tactics
Resource Development
-
T1583.001Domains -
T1588.002Tool -
T1608.001Upload Malware
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1053.005Scheduled Task -
T1203Exploitation for Client Execution -
T1204.002Malicious File -
T1559.002Dynamic Data Exchange
Privilege Escalation
Stealth
-
T1027.013Encrypted/Encoded File -
T1036.004Masquerade Task or Service
Command and Control
-
T1071.001Web Protocols -
T1095Non-Application Layer Protocol -
T1105Ingress Tool Transfer -
T1568Dynamic Resolution -
T1573Encrypted Channel
Tools & malware (1)
ZxxZ
Reporting (2)
- Bitter APT adds Bangladesh to their targets — Raghuprasad, C
- BITTER: a targeted attack against Pakistan — Dela Paz, R