Bitter leveraged phishing emails with foreign investment project lures to spread a RAR archive containing a shortcut link, which when opened prompted PowerShell execution in alternative data streams and a scheduled task that facilitates malicious curl commands, including one that retrieves WmRAT, an analysis from Proofpoint showed.