In November 2024, two C++-malware families identified as WmRAT and MiyaRAT were delivered to a Turkish defense sector business by Bitter, a suspected South Asian cyber espionage threat outfit.
In a report shared with The Hacker News, Proofpoint researchers Nick Attfield, Konstantin Klinger, Pim Trouerbach, and David Galazin claimed that the attack chain used different data streams in a RAR archive to deliver a shortcut (LNK) file that generated a scheduled task on the target machine to pull down additional payloads.
The threat actor, known as TA397, is being tracked by the enterprise security firm. The adversary is also known as APT-C-08, APT-Q-37, Hazy Tiger, and Orange Yali, and has been known to be active since at least 2013.
The hacking group’s previous efforts have targeted read more about Bitter APT Targets Turkish Defense Sector with WmRAT and MiyaRAT Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
