BITTER
G10021 reportsaliases · BITTER · T-APT-17
1
Reports
4
Techniques
3
Tactics
5
Countries
75%
Hunt coverage
2
Aliases
Analyst assessment — key judgments
- Signature techniques: T1590.005 (IP Addresses), T1036 (Masquerading), T1589.001 (Credentials).
- Primary targeting: PK, CN, IN, US.
- Currently dormant: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 75% of 4 observed techniques (1 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
DormantLast 30d: 0 vs 0 prior (+0%)· first reported 2026-07-09 · last 2026-07-09
0
7d
0
30d
1
90d
1
All
0.1
Rpts/wk
Reporting timeline · 12 months
Overview
Analyst triage
Intelligence summary
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.(Citation: Cisco Talos Bitter Bangladesh May 2022)(Citation: Forcepoint BITTER Pakistan Oct 2016)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1590.005 · IP Addressesconf 601
- T1036 · Masqueradingconf 601
- T1589.001 · Credentialsconf 601
- AML.T0074 · Masqueradingconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|