Recently, QianXin
@RedDrip7 reported a new .NET downloader attributed to
#Bitter #APT based on network infrastructure.
We also spotted the same downloader a while ago, and can confirm that it's related to
#Bitter based on code similarity with
#MuuyDownloader (another tool in their arsenal).
Both downloaders start with a similar information gathering pattern by collecting a standard set of details (Computer Name, Username, Operating System). This is a common pattern seen across multiple
#Bitter tooling.
Another shared TTP is the payload retrieval routine.
Both downloaders get the payload name from the C2 server and append the extension ".exe" to the payload filename. Then, they append the missing PE header bytes to the downloaded payload and execute it afterwards.
Samples:
bb67a4de756336d45ebaa7657a7586b4ebff26c74aba458d62de85c2070f3d90
f7e25e5601fdf038aa0840be508cf1d5915cd5317a5513cd7e7c3ae76055839f