logo

HAZY_TIGER__2019__Bitter_APT_Malware_analysis.pdf

ID: adbdf296-8d88-4500-b929-9b9caafbd115

STIX ID: report--adbdf296-8d88-4500-b929-9b9caafbd115

Threat Score

70/100

Uploaded: 2026-08-15

Published Date: 2019-09-02

Last Modified Date: 2019-09-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Malware analysis of the Bitter APT campaign describing a remote template RTF exploitation chain that delivers an ArtraDownloader/backdoor; the report details string-decoding routines, persistence via registry Run keys, system and GUID discovery, C2 beaconing (domains/IPs in Bulgaria/Ras al-Khaimah infrastructure), MITRE ATT&CK technique mappings, and a set of IOCs for detection and response.