Bitter
Malware family · 3 sample(s) · 3 indicator record(s) · 3 signing certificate(s)
About Bitter
South-Asia-nexus APT (ETDA: T-APT-17, active since 2013) whose Android payload "Dracarys" ships inside repackaged legitimate apps (documented by Meta's Q2 2022 adversarial threat report). Dracarys components live under org.zcode.dracarys.* (services.WynkService, the accessibility service AlfredService, activities.XActivity) and abuse Accessibility Services for self-granting permissions. The C2 panel is the API_URL constant in org.zcode.dracarys.config.ApiConfig; every exfiltration channel posts to <API_URL>/v3/report/<channel> while tasking arrives over Firebase messaging. A shared ProSpy code lineage links the "Beyond Bitter" hack-for-hire campaign to this actor.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| gjeikd.cdnfwersgdty.com | domain | 6c59428863dd… | 2022-10-05 |
| youtubepremiumapp.com | domain | 220fcfa47a11… | 2022-07-06 |
| 94.140.114.22:41322 | ip | 43e3a0b0d5e2… | 2022-03-22 |