HOMETHREATSHAZY TIGER
APT / THREAT GROUP

HAZY TIGER

🇮🇳India-attributed
1
campaigns
6
aliases
Last seen:Mar 17, 2026

Intelligence Profile

The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released in 2014 were based on the AndroRAT framework. Over time, they switched to a custom version that has been known as BitterRAT ever since.

Threat Analysis

HAZY TIGER is a known-sophistication threat actor attributed to India, engaged in cyber operations with a primary motivation of unknown activity patterns.

Known Campaigns

HAZY TIGER — Active Operations March 2026

HAZY TIGER is a unknown-motivation threat actor attributed to IN. The Bitter threat group initially started using RAT tools in their campaigns, as the first Bitter versions, for Android released in 2014 were based on the AndroRAT framework. Over time, they switched to a custom version that has been known as BitterRAT ever since....

ACTIVEMEDIUM2026

External References

Quick Facts

TypeAPT / Threat Group
Origin🇮🇳 India
Aliases6
SourceMalpedia

Also Known As

HAZY TIGERT-APT-17APT-C-08TA397Orange YaliBitter

Research Links

Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.
HAZY TIGER — APT / Threat Group | Threat Intelligence | CTIWATCH.COM