Bitter is an Indian state-aligned cyberespionage group active since at least 2014, conducting Windows and Android intrusion campaigns for intelligence gathering. It is also tracked as APT-C-08, Bitter APT, Hazy Tiger, Manlinghua, TA397, T-APT-17, and APT-Q-37. Its principal targets include Pakistani nationals and officials, Chinese organizations, and organizations in Saudi Arabia and Turkey. Documented sector targeting includes government, telecommunications, and defense, including Pakistani telecommunications personnel and a Turkish defense-sector organization. Bitter obtains initial access through spearphishing, malicious Office documents, deceptive Android applications, and payloads delivered through compromised websites. Its delivery chains have used Equation Editor vulnerabilities, including CVE-2017-11882, alongside macros, internet-query attachments, CHM files, shortcuts, scripts, and MSI installers. It has also used CVE-2021-1732 for Windows privilege escalation. Persistence commonly relies on registry autorun entries. Payload and infrastructure concealment includes string obfuscation, encrypted configuration and communications, execution delays, and payload reconstruction. Its evolving malware arsenal includes ArtraDownloader, MuuyDownloader, WSCSPL, BDarkRAT, AlmondRAT, WmRAT, ORPCBackdoor, MiyaRAT, KiwiStealer, and custom keylogging components. Bitter has also used the Havoc command-and-control framework during hands-on operations. Its Windows tooling supports host reconnaissance, remote command execution, screenshots, directory enumeration, file transfer, and data theft. Its Android tooling evolved from AndroRAT into BitterRAT, also called SlideRAT, with capabilities to collect messages, call histories and recordings, location information, device details, and files. Development and deployment of multiple custom malware families continued through 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
Cloud Atlas downloaded malicious RTF templates containing an exploit for CVE-2017-11882. The exploit executed shellcode in EQNEDT32.EXE and downloaded an HTA file. A similar delivery chain documented in 2018 delivered the PowerShower backdoor. The report also describes documents exploiting the same Equation Editor vulnerabilities that were attributed to Bitter APT.
While analyzing the CVE-2021-1732 exploit originally discovered by the DBAPPSecurity Threat Intelligence Center and used by the BITTER APT group, we discovered another zero-day exploit we believe is linked to the same actor.
The campaign predominantly used the older, relatively popular Microsoft Office exploit, CVE-2012-0158, in order to download and execute a RAT binary from a website.
While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence.
While the malicious RTF document exploits a memory corruption vulnerability in Microsoft Office's Equation Editor (CVE-2017-11882), the Excel file abuses two remote code execution flaws, CVE-2018-0798 and CVE-2018-0802, to activate the infection sequence.
5 more CVEs tied to this actor tracked in Mallory.
285 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection's technique annotations; the content does not attribute ShieldCrash exploitation to this group.
Listed in the detection annotation metadata.
Listed only as an annotation associated with the detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.