logo

HAZY_TIGER__2019__BITTER_APT_Not_So_Sweet.pdf

ID: e1368acc-2985-4ecb-b894-a902df3d0d88

STIX ID: report--e1368acc-2985-4ecb-b894-a902df3d0d88

Threat Score

82/100

Uploaded: 2026-08-15

Published Date: 2019-09-11

Last Modified Date: 2019-09-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report documents a BITTER APT campaign (active since ~2015) targeting Pakistani organizations by using malicious Word documents exploiting CVE-2017-11882 to download ArtraDownloader, which subsequently beacons to C2 infrastructure (e.g., onlinejohnline99.org, maq.com.pk) and likely distributes BitterRAT; the author analyzes sample behavior, network POSTs, VirusTotal pivots, hosting ISP patterns, and provides URLs and MD5 hashes as IOCs while discussing suspected regional attribution.