BITTER: A Targeted Attack Against Pakistan
ID: 9882865a-7d74-4b2c-a159-b84bc392c406
STIX ID: report--9882865a-7d74-4b2c-a159-b84bc392c406
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2016-12-31
Last Modified Date: 2016-12-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Forcepoint Security Labs documents the "BITTER" campaign — a targeted, ongoing espionage-style campaign against Pakistani targets that uses spear-phishing (CVE-2012-0158) to deliver Windows RATs and Android AndroRAT variants. The report describes RAT capabilities (remote shell, file enumeration/exfiltration), C2 mechanisms (HTTP and encrypted TCP, DDNS and hosted domains), compilation/PDB timelines, associated domains and hashes, and recommended protections to block lure, droppers, and C2 communications.
