Threat Intelligence Tarot
swords · 9
South Asia (India-linked, suspected)
G1002★★★★★
risk 3/5
✦ The Grudge ✦
Bitter
T-APT-17 · APT-C-08 · Manlinghua
PakistanChinaBangladeshNuclear energy sectorGovernment officials
Active since ~2013 · Pakistan military intelligence, Chinese government targeting, Energy sector espionage
The Grudge moves along lines of historical conflict - a South Asian actor targeting rivals across the subcontinent's fault lines. It is not the most sophisticated group in these cards, but it is relentless, and its targets feel it every day.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆Pakistan government and military targeting (ongoing)
- ◆Chinese nuclear energy organization spearphishing (2021)
- ◆ArtraDownloader and BitterRAT family deployments
- ◆Bangladesh government targeting
Defenses
- ▸Email filtering and attachment sandboxingCIS Control 9 ↗
- ▸VBA macro execution controls in Office documentsCIS Control 2 ↗
- ▸Government-sector threat intelligence sharingNIST CSF: ID.RA ↗
- ▸User awareness training for targeted government staffNIST SP 800-50 ↗
Reversed: Their Weakness
Bitter's relatively standard tooling and predictable targeting patterns have made it one of the more thoroughly attributed South Asian APT groups - the consistency of focus on Pakistan–India geopolitical tensions makes intent clear even when attribution is contested.
Share this adversary profile
swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.