HAZY_TIGER__2019__BITTER_APT_Not_So_Sweet.pdf
ID: e1368acc-2985-4ecb-b894-a902df3d0d88
STIX ID: report--e1368acc-2985-4ecb-b894-a902df3d0d88
Threat Score
82/100
Uploaded: 2026-08-15
Published Date: 2019-09-11
Last Modified Date: 2019-09-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents a BITTER APT campaign (active since ~2015) targeting Pakistani organizations by using malicious Word documents exploiting CVE-2017-11882 to download ArtraDownloader, which subsequently beacons to C2 infrastructure (e.g., onlinejohnline99.org, maq.com.pk) and likely distributes BitterRAT; the author analyzes sample behavior, network POSTs, VirusTotal pivots, hosting ISP patterns, and provides URLs and MD5 hashes as IOCs while discussing suspected regional attribution.
