August 07, 2024
Introducing the Bitter APT Group
Active for over 10 years, the Bitter threat actor has maintained an unusually frenetic pace of operations. Although occasionally derided on the sophistication scale, they have been wildly successful at completing their regional missions. In addition to first-party incidents we’ve investigated, this is also clear from use of exploited infrastructure to attack subsequent targets. They’ve been willing to burn accesses that other groups would have kept close held. This blog sheds light on their latest activities, including previously untracked IOCs, and provides analysis of their manually dropped payloads.