Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteMeta said it disrupted two cyberespionage operations in South Asia in its Q2 2022 Adversarial Threat Report, published August 4, 2022. It linked one operation to Bitter APT and described the other, APT36, as linked to state actors in Pakistan. These are Meta’s historical findings, not evidence of either group’s current activity.
What Meta reported
Meta’s report states: “We took action against two cyber espionage operations in South Asia.” The report lists Ben Nimmo, Global Threat Intelligence Lead, and David Agranovich, Director, Threat Disruption, as authors. Meta’s report page describes the two operations and the company’s response.
The available report details are not equally extensive for both operations. Meta’s account provides target countries and methods for Bitter APT, while the accessible material establishes only its attribution of APT36 to state-linked actors in Pakistan. The distinction matters: details about one operation should not be assumed to describe the other.
How Meta described the two operations
| Operation | Meta’s attribution | Geographic scope and methods described |
|---|---|---|
| Bitter APT | Meta linked the operation to Bitter APT. | Meta said it operated out of South Asia and targeted people in New Zealand, India, Pakistan, and the United Kingdom. It described social engineering and malware distribution using link-shortening services, malicious domains, compromised websites, and third-party hosting. |
| APT36 | Meta described the operation as linked to state actors in Pakistan. | Specific target countries and methods are not stated in the accessible report excerpt. |
What Meta said about Bitter APT’s approach
Meta characterized Bitter’s activity as relatively low in sophistication and operational security, yet persistent and well-resourced. Its description points to an approach that relied on social engineering and distributing malware through varied online infrastructure, rather than requiring every delivery attempt to use a highly sophisticated technique.
#1 Best Overall
Link shorteners, compromised websites, malicious domains, and third-party hosting can give a malicious link or file multiple routes to a target. Meta’s account does not provide a numerical count of affected accounts, targeted people, or malware samples in the accessible material, so those totals should not be inferred.
What Meta did to disrupt the operations
Meta said its response included actions on its services and coordination beyond them:
- It removed accounts associated with the operations.
- It blocked the networks’ domain infrastructure from being shared on its services.
- It notified people it believed had been targeted.
- It shared findings with security researchers and industry peers.
Meta also said the report’s appendix included threat indicators such as malware hashes and command-and-control infrastructure. The accessible material does not state a total number of indicators.
Why Meta highlighted openly available tools
Meta’s broader observation was that advanced persistent threat (APT) operators were increasingly using openly available malicious tools, including open-source malware, rather than always developing or buying sophisticated capabilities. In Meta’s framing, inexpensive, accessible tools can lower the barrier to cyberespionage and help operators blend into background activity.
Rank #3
This is a general observation in the report, not a claim that every tool used in the two South Asia operations was open-source or that the same methods remain in use today.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the report does and does not establish
The findings should be read as Meta’s attribution and account of its own platform response. They do not, by themselves, establish independent confirmation of the groups’ identities or describe their present-day activity. Meta’s accessible account gives concrete target-country and tactic details for Bitter APT, but substantially less detail about APT36. No APT36 target list, specific tactics, or full attribution evidence is established in the material cited here.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

