A China-linked threat group primarily targeting gambling websites with multi-platform malware.
Analyst brief
Earth Berberoka (GamblingPuppet) is a threat group likely originating from China, primarily focusing on targeting gambling websites. They target the gambling, IT, electronics manufacturing, and education sectors in China, the US, Hong Kong, Malaysia, and Taiwan. The group employs upgraded malware families like PlugX and Gh0st RAT, alongside a new multistage malware called PuppetLoader, across Windows, Linux, and macOS platforms. Defenders should prioritize detecting targeted phishing and C2 traffic, and specifically focus on identifying the multi-stage infection chain of PuppetLoader.
Earth Berberoka
GamblingPuppet
unknown
According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign uses multiple malware families that target the Windows, Linux, and macOS platforms that have been attributed to Chinese-speaking actors. Aside from using tried-and-tested malware families that have been upgraded, such as PlugX and Gh0st RAT, Earth Berberoka has also developed a brand-new complex, multistage malware family, which has been dubbed PuppetLoader.