logo

Bitter APT Targets Turkish Defense Sector with WmRAT and MiyaRAT Malware

ID: 0900865c-d331-5c27-815f-e1045533d78f

STIX ID: report--0900865c-d331-5c27-815f-e1045533d78f

Feed Name: Proofpoint Blog

Threat Score
85/100

Date Published: 2024-12-17

Date Updated: 2026-04-28

...
...

Proofpoint researchers observed the Bitter (TA397) APT conduct a November 2024 espionage operation against a Turkish defense organization using a booby-trapped RAR attachment that leveraged NTFS alternate data streams and a malicious LNK to create scheduled tasks and retrieve two RAT families (WmRAT and MiyaRAT). The report details the delivery and persistence techniques, RAT capabilities (data exfiltration, file transfer, command execution, screenshots, geolocation), and links the activity to Bitter's prior nation-state-focused campaigns across South and East Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.