Skip Navigation

June 15, 2025 |

Weekly threat roundup: TA397, also known as Bitter

Loading table of contents...

Proofpoint links TA397 to Indian State

Researchers at Proofpoint reported on activity of TA397 (aka Bitter), an espionage group with a history of targeting South Asian entities. The report establishes TA397 as an "espionage-focused, state-backed threat actor, tasked with intelligence gathering in the interests of the Indian state".

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up

More details:

Some evidence of that is that its operations aligning with the standard working hours of the Indian Standard Time (IST) time zone and are consistent with activity that is in the intelligence interests of the Indian state.

The report also highlights that the threat actor targets a much wider range of regions than previously documented, including European entities, China, and South America.

India is a rising cyber actor and we’ll be observing the activity by this actor more closely.