Earth Berberoka

Aliases: GamblingPuppet

Origin
CN
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Last IoC activity
2026-07-06 12:37:04
Profile updated
2026-07-07 12:02:09

Targeted industries: retail-and-hospitality technology-and-telecommunications

Context

According to TrendMicro, Earth Berberoka is a threat group originating from China that mainly focuses on targeting gambling websites. This group's campaign uses multiple malware families that target the Windows, Linux, and macOS platforms that have been attributed to Chinese-speaking actors. Aside from using tried-and-tested malware families that have been upgraded, such as PlugX and Gh0st RAT, Earth Berberoka has also developed a brand-new complex, multistage malware family, which has been dubbed PuppetLoader.

Reports & references

  • Trend Micro — Wp Operation Earth Berberoka (report)
  • Trend Micro — New Apt Group Earth Berberoka Targets Gambling Websites With Old (report)
  • Trend Micro — Earth Berberoka Windows Iocs 2.Txt (report)
  • Trend Micro — Earth Berberoka Linux Iocs 2.Txt (report)
  • Trend Micro — Earth Berberoka Macos Iocs 2.Txt (report)
  • Trend Micro — Earth Berberoka Domains 2.Txt (report)
  • youtube.com — Watch (report)
  • botconf.eu — Botconf2022 40 Lunghihorejsi (report)
  • Kaspersky — 107723 (report)
  • Trend Micro — Irontiger Compromises Chat App Mimi Targets Windows Mac Linux Users (report)

External references