Also known as: GamblingPuppet
According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign uses multiple malware families that target the Windows, Linux, and macOS platforms that have been attributed to Chinese-speaking actors. Aside from using tried-and-tested malware families that have been upgraded, such as PlugX and Gh0st RAT, Earth Berberoka has also developed a brand-new complex, multistage malware family, which has been dubbed PuppetLoader.
Targeted Sectors
Executive Summary
Earth Berberoka, also known as GamblingPuppet, is a threat group linked to China targeting gambling websites and IT/education sectors. They employ a mix of legacy malware like PlugX and Gh0st RAT, alongside a novel multistage malware family called PuppetLoader. Their operations span multiple platforms, suggesting a focus on infiltrating and exploiting critical infrastructure in targeted sectors.
Goals & Targeting
Earth Berberoka's targeting of gambling websites and IT/education sectors suggests a strategic focus on industries with high-value data or infrastructure vulnerabilities. The gambling sector's reliance on secure transactions and user-sensitive information may be a primary target for data theft or financial gain. The IT and education sectors are likely targeted for their role in maintaining critical infrastructure or as a stepping stone for further attacks. The group's use of both legacy and novel malware indicates a goal of maintaining long-term access to systems, possibly for espionage, ransomware deployment, or disruption. Their operational scope may aim to exploit geopolitical or economic interests tied to their origin region.
Enhanced Description
Earth Berberoka is a threat actor originating from China, primarily targeting gambling websites and expanding into information-technology and education sectors. The group leverages both established and newly developed malware families, including PlugX, Gh0st RAT, and the custom PuppetLoader, which is noted for its multistage attack architecture. This indicates a high degree of technical sophistication, with the capability to adapt and evolve their toolset. The group's use of cross-platform malware (Windows, Linux, macOS) suggests an intent to compromise diverse environments, potentially to maximize access or extract sensitive data. While the group's primary motivation remains unclear, their focus on gambling websites implies an interest in financial sectors or data exploitation. The group's activities are consistent with state-sponsored or financially motivated actors, though definitive attribution remains unconfirmed. Their operations suggest a calculated approach to infiltration, possibly involving spear-phishing, exploitation of software vulnerabilities, and lateral movement within targeted networks.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Berberoka's campaigns exhibit a preference for targeting gambling-related infrastructure, with a secondary focus on IT and education sectors. Their operations involve a blend of known malware families and custom tools, suggesting a dual strategy of leveraging existing capabilities while developing new, complex payloads. The group's use of multi-stage malware hints at a prolonged engagement with targets, potentially for sustained surveillance or financial exploitation. Notable campaigns have involved the deployment of PuppetLoader, which may be used to exfiltrate data or establish persistent access. However, detailed campaign timelines or specific victim examples are not publicly documented.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the provided data is moderate due to gaps in specific victim examples, first/last seen dates, and detailed operational timelines. While the group's use of PlugX, Gh0st RAT, and PuppetLoader is well-documented, the exact motivation and primary countries targeted remain unclear. MITRE technique inferences are based on tool behavior rather than direct attribution, introducing potential inaccuracies. Further intelligence collection is required to validate the group's geopolitical ties and refine capability assessments.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics