Adversary Intelligence — 2026-04-11

BITTER APT Group Linked to Indian Government Runs Hack-for-Hire Operation Targeting Middle East Journalists

Lookout, Access Now, and SMEX exposed a hack-for-hire operation linked to the BITTER APT group, assessed to conduct intelligence gathering for the Indian government. The campaign targeted Egyptian journalists Mostafa Al-A'sar and Ahmed Eltantawy plus a Lebanese journalist using ProSpy Android spyware and OAuth phishing. Technical analysis found shared infrastructure with earlier BITTER Dracarys malware, including the com-ae[.]net domain and code-level naming conventions.

Analysis
The BITTER group's continued targeting of Middle East journalists during active conflict suggests a state customer, assessed as India, is paying for surveillance on media figures who may have access to conflict zone sources. The hack-for-hire model allows state actors to maintain plausible deniability while acquiring intelligence from environments where their own services lack access.
2 sources
  1. Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region - The Hacker News
  2. Beyond BITTER: MENA Civil Society Targeted in Hack-For-Hire Operation - Lookout

View in full brief →

UNCLASSIFIED // OPEN SOURCE