Earth Berberoka - Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:42:54 UTC Home > List all groups > Earth Berberoka APT group: Earth Berberoka Names Earth Berberoka (Trend Micro) GamblingPuppet (Trend Micro) Country China Motivation Information theft and espionage First seen 2022 Description (Trend Micro) We recently discovered a new advanced persistent threat (APT) group that we have dubbed Earth Berberoka (aka GamblingPuppet). Based on our analysis, this group targets gambling websites. Our investigation has also uncovered that Earth Berberoka targets the Windows, Linux, and macOS platforms, and uses malware families that have been historically attributed to Chinese-speaking individuals. Observed Sectors: Casinos and Gambling. Countries: Southeast Asia. Tools used AsyncRAT, Gh0st RAT, oRAT, PlugX, PuppetLoader, QuasarRAT, Trochilus RAT. Information Last change to this card: 03 May 2022 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=8051fd82-774c-49ee-8efe-c1125acda67b https://apt.etda.or.th/cgi-bin/showcard.cgi?u=8051fd82-774c-49ee-8efe-c1125acda67b Page 1 of 1