ZxxZ
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 02/06/2022 14:27
- Modified
- 27/03/2026 01:05
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 27 attack patterns (mitre), 1 intrusion sets (apt), 1 sectors, 1 countries, 21 indicators, 1 vulnerabilities (cve)
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (27)
-
T1608 usesStage Capabilities MITRE
-
T1053.005 usesScheduled Task MITRE
-
-
T1083 usesFile and Directory Discovery MITRE
-
T1068 usesExploitation for Privilege Escalation MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1105 usesIngress Tool Transfer MITRE
-
Multi-Stage Channels usesT1104 MITRE
-
T1203 usesExploitation for Client Execution MITRE
-
T1518.001 usesSecurity Software Discovery MITRE
-
T1036.004 usesMasquerade Task or Service MITRE
Intrusion sets (APT) (1)
-
The MITRE Corporation Confidence 100
[BITTER](https://attack.mitre.org/groups/G1002) is a suspected South Asian cyber espionage threat group that has been active since at least 2013. [BITTER](https://attack.mitre.org/groups/G1002) has targeted government, energy, and engineering organizations in Pakistan,…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (1)
-
Defense ministries (including the military) targets
Countries (1)
-
Bangladesh targets
Indicators (21)
-
stix 100/100 Revoked
Zpevdo
· Valid until 09/10/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 09/10/2023 · Source: AlienVault
-
dd1c6d6276efba12eff01052033aa3a3717f3af9indicatesyara 100/100 RevokedDetects Bitter (T-APT-17) shellcode in oleObject (CVE-2018-0798)
· Valid until 09/10/2023 · Source: AlienVault -
stix 100/100 Revoked
Zpevdo
· Valid until 09/10/2023 · Source: AlienVault -
stix 100/100 Revoked
Bitter
· Valid until 09/10/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 09/10/2023 · Source: AlienVault
-
stix 100/100 Revoked
Bitter SHA256 of c330ef43bbee001296c6c120cf68e4c90d078d9c
· Valid until 09/10/2023 · Source: AlienVault -
http://emshedulersvc.com/vc/vcindicatesstix 100/100 Revoked· Valid until 22/08/2022 · Source: AlienVault
Vulnerabilities (CVE) (1)
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code …
- Published
- 03/11/2021
- Modified
- 27/05/2026