ArtraDownloader is a Windows downloader associated with the Bitter espionage group, also tracked as TA397, APT-C-08, and T-APT-17. First observed in 2016, it is one of the earliest known malware families in Bitter’s toolset and has been used in intelligence-gathering campaigns targeting government and other organizations in South Asia and the Middle East, including victims in Pakistan and Saudi Arabia.
Written in C++, ArtraDownloader performs basic host reconnaissance by collecting system information such as username, computer name, and operating system details, generating a victim identifier, and transmitting that information to command-and-control infrastructure over HTTP or HTTPS. Its primary role is to retrieve and execute additional payloads on compromised systems. Observed follow-on payloads include a Bitter keylogger, the WSCSPL backdoor, and BDarkRAT. Persistence is established through self-copying and use of Windows Run key autorun mechanisms.
Multiple ArtraDownloader variants have been documented. Differences between variants are mainly in string-obfuscation routines, HTTP request formatting, and command-and-control response handling rather than core functionality. The malware commonly uses simple character-based encoding or decoding for embedded strings and transmitted data, reflecting the broader development patterns seen across Bitter malware families.
ArtraDownloader has been delivered through spearphishing and malicious documents, including weaponized files exploiting CVE-2017-11882, as well as malicious executables hosted on compromised legitimate websites. Its use fits Bitter’s longstanding operational model of targeted espionage, staged payload delivery, and selective deployment of more capable implants after initial victim profiling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One of the files, Port Details.doc is an RTF document crafted to exploit the EQNEDT vulnerability CVE-2017-11882. ... This payload is an instance of ArtraDownloader variant 1 exploits CVE-2017-11882 (EQNEDT). | Between mid-September 2018 and January 2019, Unit 42 observed the ArtraDownloader used in the targeting of Pakistan and Saudi Arabian organizations.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
Bitter (aka APT-C-08 or T-APT-17) is suspected to be a South Asian hacking group motivated primarily by intelligence gathering, an operation that's facilitated by means of malware such as BitterRAT, ArtraDownloader, and AndroRAT.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The first known family used by Bitter is ArtraDownloader. First appearing in 2016... ArtraDownloader is a simple downloader written in C++.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\JITDfbug - "cmd /c start %Qrp% && exit"
The keylogger lacks exfiltration capabilities, requiring deployment alongside another module (such as the WSCSPL backdoor) to handle the exfiltration of collected logs.
Both payloads were observed in InPage exploits. | One of the files, Port Details.doc is an RTF document crafted to exploit the EQNEDT vulnerability CVE-2017-11882.
Cisco Talos attributed the activity with moderate confidence to a hacking group dubbed the Bitter APT based on overlaps in the command-and-control (C2) infrastructure with that of prior campaigns mounted by the same actor.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
C++ downloader that performs system information collection and retrieves/executes a remote payload over HTTP.
ArtraDownloader is a downloader used by TA397 to deploy additional payloads. It collects the username and computer name from infected machines and sends them to the C2 server for victim selection and further payload delivery.
A C++ downloader that gathers basic system information, generates a victim identifier, communicates with C2 to retrieve a payload filename, downloads the next-stage payload, executes it, and establishes persistence via the Run registry key.
A downloader malware family associated with Bitter APT and used in support of intelligence-gathering campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.