Operation DRBControl

First seen
2019-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:19:56

Targeted industries: retail-and-hospitality technology-and-telecommunications

Targeted regions: country_code:ph country_code:th country_code:my

Context

Operation DRBControl is a cyberespionage campaign targeting gambling companies in Southeast Asia, first identified in 2019. The operation involves the use of HyperBro malware and SysUpdate variants, with evidence of customer database and source code exfiltration. The threat actor has employed domain spoofing for command and control and has shown a consistent interest in the gambling industry. Trend Micro's analysis linked multiple tools and malware families to this campaign, indicating a sophisticated and evolving threat landscape.

Reports & references

  • Trend Micro — Operation Drbcontrol Uncovering A Cyberespionage Campaign Targeting Gambling Companies In Southeast Asia (report)

External references