216.73.216.6

Bitter (APT-Q-37) uses diverse means to deliver new backdoor components

· Published 23/10/2025 08:07 · Modified 23/10/2025 08:38

Export JSON

Essential information

Published
23/10/2025 08:07
Modified
23/10/2025 08:38
Tags
2025-10-23 apt-q-37 winrar vulnerability
Related entities
1 vulnerabilities (cve), 19 observables, 1 intrusion sets (apt), 17 techniques (mitre), 1 malware, 5 others

Description

The Bitter group, also known as , has been detected using new attack techniques to deliver a C# backdoor. Two attack chains were identified: one using VBA macros in xlam files to compile and install the backdoor, and another exploiting a to plant malicious macros. The backdoor communicates with C2 servers, collects device information, and can download and execute arbitrary EXE files. The group, believed to have South Asian origins, targets government, electric power, and military industries in China, Pakistan, and other countries. The attacks demonstrate the group's evolving tactics and expansion of their arsenal, although some methods require specific victim environments to succeed.

External references