ArtraDownloader is a C++ downloader for Windows used by the espionage threat actor Bitter, also tracked as APT-C-08, T-APT-17, and TA397. First identified in 2016, it serves as an early-stage payload that collects the infected system's username, computer name, and operating system information, generates a victim identifier, and transmits identifying information to command-and-control infrastructure. It retrieves and executes additional payloads through HTTP-based communications. Observed follow-on payloads include a keylogger, the WSCSPL backdoor, and BDarkRAT; these modules provide capabilities beyond those of the downloader itself.
ArtraDownloader establishes persistence by copying itself to a predetermined location and configuring a Windows registry Run entry. Variants differ primarily in string obfuscation, HTTP request formats, and command-and-control response identifiers. Simple byte addition or subtraction is used to obscure important strings and encode transmitted information. Distribution has involved malicious documents, document-disguised executables, and payload hosting on compromised legitimate websites. Infection chains have used Microsoft Equation Editor exploitation through CVE-2017-11882, and ArtraDownloader activity has also involved InPage exploits. Campaigns observed between September 2018 and January 2019 targeted organizations in Pakistan and Saudi Arabia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One of the files, Port Details.doc is an RTF document crafted to exploit the EQNEDT vulnerability CVE-2017-11882. ... This payload is an instance of ArtraDownloader variant 1 exploits CVE-2017-11882 (EQNEDT). | Between mid-September 2018 and January 2019, Unit 42 observed the ArtraDownloader used in the targeting of Pakistan and Saudi Arabian organizations.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The Bitter threat group has been using ArtraDownloader for its Windows campaign [10] and AndroRAT variations for its Android campaigns.”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\JITDfbug - "cmd /c start %Qrp% && exit"
The keylogger lacks exfiltration capabilities, requiring deployment alongside another module (such as the WSCSPL backdoor) to handle the exfiltration of collected logs.
Both payloads were observed in InPage exploits. | One of the files, Port Details.doc is an RTF document crafted to exploit the EQNEDT vulnerability CVE-2017-11882.
Cisco Talos attributed the activity with moderate confidence to a hacking group dubbed the Bitter APT based on overlaps in the command-and-control (C2) infrastructure with that of prior campaigns mounted by the same actor.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ downloader that performs system information collection and retrieves/executes a remote payload over HTTP.
ArtraDownloader is a downloader used by TA397 to deploy additional payloads. It collects the username and computer name from infected machines and sends them to the C2 server for victim selection and further payload delivery.
A C++ downloader that gathers basic system information, generates a victim identifier, communicates with C2 to retrieve a payload filename, downloads the next-stage payload, executes it, and establishes persistence via the Run registry key.
A downloader malware family associated with Bitter APT and used in support of intelligence-gathering campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.