DiceyF is an APT group targeting online casinos in Southeast Asia for espionage and intellectual property theft.
Analyst brief
DiceyF is an advanced persistent threat group of unclear origin that primarily targets online casinos and other entities in Southeast Asia. Their operations appear motivated by espionage and intellectual property theft rather than immediate financial gain. The group continuously evolves its codebase with new encryption capabilities and shares TTP overlaps with tracked clusters like LuckyStar PlugX and GamblingPuppet. Defenders should focus on detecting encrypted C2 communications, PlugX variant indicators, and stealthy network anomalies, especially within the online casino sector.
DiceyF
unknown
DiceyF is an advanced persistent threat group that has been targeting online casinos and other victims in Southeast Asia for an extended period. They have exhibited overlapping activity with LuckyStar PlugX and Earth Berberoka/GamblingPuppet, as reported by various cybersecurity vendors. While their motivations remain unclear, previous incidents suggest a combination of espionage and intellectual property theft rather than immediate financial gain. DiceyF continuously evolves their codebase and adds encryption capabilities to enhance their stealthy cyberespionage activities.