Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Berberoka

Also known as: GamblingPuppet

Description

According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign uses multiple malware families that target the Windows, Linux, and macOS platforms that have been attributed to Chinese-speaking actors. Aside from using tried-and-tested malware families that have been upgraded, such as PlugX and Gh0st RAT, Earth Berberoka has also developed a brand-new complex, multistage malware family, which has been dubbed PuppetLoader.

Goals & Targeting

Targeted Sectors

Information technology
Education

AI Analysis

· 1 week ago

Executive Summary

Earth Berberoka, also known as GamblingPuppet, is a threat group linked to China targeting gambling websites and IT/education sectors. They employ a mix of legacy malware like PlugX and Gh0st RAT, alongside a novel multistage malware family called PuppetLoader. Their operations span multiple platforms, suggesting a focus on infiltrating and exploiting critical infrastructure in targeted sectors.

Goals & Targeting

Earth Berberoka's targeting of gambling websites and IT/education sectors suggests a strategic focus on industries with high-value data or infrastructure vulnerabilities. The gambling sector's reliance on secure transactions and user-sensitive information may be a primary target for data theft or financial gain. The IT and education sectors are likely targeted for their role in maintaining critical infrastructure or as a stepping stone for further attacks. The group's use of both legacy and novel malware indicates a goal of maintaining long-term access to systems, possibly for espionage, ransomware deployment, or disruption. Their operational scope may aim to exploit geopolitical or economic interests tied to their origin region.

Enhanced Description

Earth Berberoka is a threat actor originating from China, primarily targeting gambling websites and expanding into information-technology and education sectors. The group leverages both established and newly developed malware families, including PlugX, Gh0st RAT, and the custom PuppetLoader, which is noted for its multistage attack architecture. This indicates a high degree of technical sophistication, with the capability to adapt and evolve their toolset. The group's use of cross-platform malware (Windows, Linux, macOS) suggests an intent to compromise diverse environments, potentially to maximize access or extract sensitive data. While the group's primary motivation remains unclear, their focus on gambling websites implies an interest in financial sectors or data exploitation. The group's activities are consistent with state-sponsored or financially motivated actors, though definitive attribution remains unconfirmed. Their operations suggest a calculated approach to infiltration, possibly involving spear-phishing, exploitation of software vulnerabilities, and lateral movement within targeted networks.

Key Capabilities

  • Use of cross-platform malware (Windows, Linux, macOS)
  • Deployment of custom multistage malware (PuppetLoader)
  • Exploitation of legacy malware families (PlugX, Gh0st RAT)
  • Sophisticated command-and-control (C2) infrastructure management
  • Ability to conduct spear-phishing campaigns with targeted payloads
  • Lateral movement and persistence techniques within compromised networks

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1197
T1071.001
T1570

Software / Tooling

PlugX
Gh0st RAT
PuppetLoader

Campaigns & Victims

Earth Berberoka's campaigns exhibit a preference for targeting gambling-related infrastructure, with a secondary focus on IT and education sectors. Their operations involve a blend of known malware families and custom tools, suggesting a dual strategy of leveraging existing capabilities while developing new, complex payloads. The group's use of multi-stage malware hints at a prolonged engagement with targets, potentially for sustained surveillance or financial exploitation. Notable campaigns have involved the deployment of PuppetLoader, which may be used to exfiltrate data or establish persistent access. However, detailed campaign timelines or specific victim examples are not publicly documented.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over DNS using fast-flux techniques
  • Staging infrastructure on bulletproof hosting services
  • Payload delivery via exploit kits targeting unpatched software
  • Use of domain generation algorithms (DGAs) for C2 resilience

Recommended Actions

  • Implement network monitoring for DNS anomalies and fast-flux C2 patterns
  • Deploy endpoint detection and response (EDR) solutions to detect PuppetLoader behavior
  • Conduct regular phishing simulations and user training for IT/education sector staff
  • Ensure timely patching of software vulnerabilities exploited by PlugX/Gh0st RAT
  • Isolate and segment gambling-related infrastructure to limit lateral movement risks

Suggested Tags

APT
espionage
financial-sector
information-technology
education-sector

Confidence Assessment

Confidence in the provided data is moderate due to gaps in specific victim examples, first/last seen dates, and detailed operational timelines. While the group's use of PlugX, Gh0st RAT, and PuppetLoader is well-documented, the exact motivation and primary countries targeted remain unclear. MITRE technique inferences are based on tool behavior rather than direct attribution, introducing potential inaccuracies. Further intelligence collection is required to validate the group's geopolitical ties and refine capability assessments.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
financial-sector
information-technology
education-sector

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.