Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DiceyF

Description

DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended period. They have exhibited overlapping activity with LuckyStar PlugX and Earth Berberoka/GamblingPuppet, as reported by various cybersecurity vendors. While their motivations remain unclear, previous incidents suggest a combination of espionage and intellectual property theft rather than immediate financial gain. DiceyF continuously evolves their codebase and adds encryption capabilities to enhance their stealthy cyberespionage activities.

AI Analysis

· 1 week ago

Executive Summary

DiceyF is an advanced persistent threat group targeting online casinos and other entities in Southeast Asia, likely engaging in espionage and intellectual property theft. The group overlaps with known threat actors like LuckyStar PlugX and Earth Berberoka/GamblingPuppet, using evolving malware with encryption capabilities to remain stealthy.

Goals & Targeting

DiceyF's targeting of Southeast Asian online casinos and related sectors suggests an interest in acquiring sensitive data, such as customer information, operational strategies, or proprietary technologies. The group's emphasis on espionage and IP theft implies a strategic goal of gaining competitive advantages or conducting state-sponsored intelligence gathering. The focus on Southeast Asia may be driven by the region's growing digital economy and the presence of high-value targets within the gaming and financial sectors.

Enhanced Description

DiceyF has been actively targeting online casinos and other victims across Southeast Asia for an extended period. The group exhibits a high level of sophistication, regularly updating its malware codebase and integrating encryption to avoid detection. Cybersecurity vendors have observed overlap with the LuckyStar PlugX and Earth Berberoka/GamblingPuppet groups, suggesting potential shared infrastructure or tactics. While DiceyF's motivations are not explicitly clear, historical activity indicates a focus on espionage and intellectual property theft rather than direct financial gain. The group's operations emphasize stealth, suggesting a long-term strategic objective of data exfiltration and persistent access to compromised networks.

Key Capabilities

  • Advanced encryption implementation in malware
  • Stealthy cyberespionage operations
  • Custom malware development and codebase evolution
  • Persistence mechanisms for long-term access
  • Targeted phishing campaigns against specific sectors

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Data Exfiltration
Command and Control

ATT&CK Techniques

T1055.002 - Remote Code Execution via Exploit
T1025 - Custom C2 Protocol
T1132.001 - Application Layer Protocol Tunneling
T1566.001 - Phishing
T1059.003 - Command-Line Interface

Software / Tooling

LuckyStar PlugX
Earth Berberoka
GamblingPuppet
Custom Encrypted RAT

Campaigns & Victims

DiceyF's campaigns focus on Southeast Asian online casinos and related industries, utilizing techniques seen in associated groups such as LuckyStar PlugX. The group's operational tempo suggests sustained, long-term campaigns with a focus on stealth and encryption. Notable past activities include overlapping infrastructure use and continuous malware evolution, indicating a commitment to maintaining access and avoiding detection by security systems.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over encrypted protocols (e.g., HTTPS, DNS)
  • Staging infrastructure on bulletproof hosting services
  • Custom payloads with obfuscated code

Recommended Actions

  • Implement advanced phishing detection and employee training programs
  • Monitor for anomalous network traffic indicative of encrypted C2 communications
  • Deploy endpoint detection systems to identify custom malware behavior
  • Conduct regular threat hunting exercises focused on Southeast Asian threat actor signatures
  • Leverage threat intelligence feeds from vendors tracking DiceyF and associated groups

Suggested Tags

APT
espionage
Southeast Asia
online-casinos
intellectual-property-theft

Confidence Assessment

The analysis is based on overlapping activity reports from cybersecurity vendors and observed malware behavior, which provides medium to high confidence in DiceyF's targeting and capabilities. However, gaps remain in confirmed motivations, full MITRE technique mapping, and specific attribution to individual campaigns. Further analysis of malware samples and network traffic would improve confidence levels.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Data Exfiltration
espionage
Southeast Asia
online-casinos
intellectual-property-theft

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.