logo

'Bitter' cyberspies target defense orgs with new MiyaRAT malware

ID: 5ca0fb24-07c9-5dfa-8103-c8ca4805da2e

STIX ID: report--5ca0fb24-07c9-5dfa-8103-c8ca4805da2e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-17

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Proofpoint observed the APT group Bitter targeting Turkish defense organizations with a new RAT family (MiyaRAT) used alongside WmRAT; the attackers delivered a RAR containing a decoy PDF, an LNK file, and alternate data streams that execute PowerShell, create a scheduled task to call a staging domain (jacknwoods.com), and fetch additional payloads, with IoCs and a YARA rule provided for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.