logo

BITTER: A Targeted Attack Against Pakistan

ID: 9882865a-7d74-4b2c-a159-b84bc392c406

STIX ID: report--9882865a-7d74-4b2c-a159-b84bc392c406

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2016-12-31

Last Modified Date: 2016-12-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Forcepoint Security Labs documents the "BITTER" campaign — a targeted, ongoing espionage-style campaign against Pakistani targets that uses spear-phishing (CVE-2012-0158) to deliver Windows RATs and Android AndroRAT variants. The report describes RAT capabilities (remote shell, file enumeration/exfiltration), C2 mechanisms (HTTP and encrypted TCP, DDNS and hosted domains), compilation/PDB timelines, associated domains and hashes, and recommended protections to block lure, droppers, and C2 communications.