Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: T-APT-17
16
techniques
1
software
11,346
corpus matches
profile
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.
techniques
16 attributed · most-instrumented first
software
1 malware & tools attributed
ZxxZ
S1013
read this carefully
11,346 corpus matches is not attribution
That count is indicators which exhibit techniques BITTER is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+4 more techniques
showing 30 of 11,346
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.