June 27, 2026
- Bitter APT (APT-C-08) is hitting maritime and government officials with a
.accdrfile disguised as a PDF: AutoExec VBA fires on open, decodes payloads in memory via MSXML2, side-loads a DLL through signedfsquirt.exe, and plants a 17-minute scheduled task masquerading as a Chrome updater that pipes C2 responses straight intocmd.exe. The DLL runs TLS-callback anti-analysis and WMI/BIOS VM checks before fetching stage two. Nextron Research · Threat Activity