[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fk2KdNrsuiva7IZvp-THwj8n8rFHSYOzFgevjAwa3o48":3},{"article":4,"iocs":47,"watch_terms":58},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":31},"29f4a78c-45c3-4c01-9f94-3dba458696e9","Detection Insight: Suspicious .accdr Dropper Activity (Possible Bitter Tradecraft)\n\nA recent our...","detection-insight-suspicious-accdr-dropper-activity-possible-bitter-tradecraft-a-409907","Detection Insight: Suspicious .accdr Dropper Activity (Possible Bitter Tradecraft)\n\nA recent our rules uncovered a cluster of Microsoft Access Runtime files (.accdr) behaving as stealthy droppers - most of them showing extremely low antivirus detection (0\u002F62)\n\n🔍 Detection https:\u002F\u002Ft.co\u002FgzQdJmu94R","Security researchers identified a cluster of malicious Microsoft Access Runtime (.accdr) files functioning as droppers, potentially linked to Bitter threat actor tradecraft. The files exhibited extremely low antivirus detection rates (0\u002F62), suggesting sophisticated evasion techniques. This indicates an active campaign leveraging legitimate Office file formats for payload delivery.","Microsoft Access Runtime .accdr files detected as stealthy droppers with minimal AV coverage.",null,"https:\u002F\u002Fx.com\u002Fnextronresearch\u002Fstatus\u002F2049131171808739667","https:\u002F\u002Fpbs.twimg.com\u002Fmedia\u002FHG_5vtPaQAA5Pid.png","2026-04-28T14:18:37+00:00","2026-04-28T15:00:12.915416+00:00",8,[18,21,24],{"name":19,"type":20},"Bitter","threat_actor",{"name":22,"type":23},"Microsoft Access Runtime","product",{"name":25,"type":26},".accdr file format","technology","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":27,"icon":11,"name":29,"slug":30},"Malware","malware",[32,37,42],{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":43},{"id":44,"icon":11,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[48,51,55],{"type":30,"value":49,"context":50},".accdr dropper","Suspicious Microsoft Access Runtime files behaving as stealthy droppers with 0\u002F62 AV detection",{"type":52,"value":53,"context":54},"mitre_attack","T1566.001","Phishing - spearphishing attachment using Office file format",{"type":52,"value":56,"context":57},"T1140","Deobfuscate\u002FDecode Files and Information - evasion via file format abuse",[22]]