Bitter

Description

(Forcepoint) Forcepoint Security Labs recently encountered a strain of attacks that appear to target Pakistani nationals. We named the attack “BITTER” based on the network communication header used by the latest variant of remote access tool (RAT) used.

Our investigation indicates that the campaign has existed since at least November 2013 but has remained active until today.

Names

NameName-Giver
BitterForcepoint
T-APT-17Tencent
TA397Proofpoint

Country

Motivation

  • Information theft and espionage

First Seen

2013

Observed Sectors

Observed Countries

Tools

Operations

Information

Mitre Attack

Other Information

Uuid

3566178c-4075-46be-bd5c-d4eccf7fa8c0

Last Card Change

2025-06-30