HAZY TIGER is a threat actor active since 2014, known for custom RAT tools and targeted spearphishing attacks.
Analyst brief
HAZY TIGER (also known as Bitter, T-APT-17) is a threat actor active since 2014, known for using custom RAT tools. The group currently targets victims in Germany. Their key TTPs include initial access via Spearphishing Attachment, execution through Dynamic Data Exchange (DDE), use of the ZxxZ (BitterRAT) malware, and Web Protocols for command and control. Defenders should enhance monitoring for DDE exploitation, scrutinize suspicious email attachments, and inspect web traffic for C2 anomalies.
HAZY TIGER
BitterT-APT-17APT-C-08
unknown
The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released in 2014 were based on the AndroRAT framework. Over time, they switched to a custom version that has been known as BitterRAT ever since.