Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 22:57:49 UTC Home > List all groups > List all tools > List all groups using tool PuppetLoader Tool: PuppetLoader Names PuppetLoader Category Malware Type Loader Description (Trend Micro) We discovered a new malware family that we have dubbed PuppetLoader. It is a complex, five-stage malware family that uses some interesting techniques, including hijacking loaded modules to launch malicious code and hiding malicious payloads and modules in modified bitmap image (BMP) files. Information Last change to this tool card: 03 May 2022 Download this tool card in JSON format All groups using tool PuppetLoader Changed Name Country Observed APT groups   Earth Berberoka 2022   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=883f8c01-c81d-4e25-bd80-eacb7670d0e1 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=883f8c01-c81d-4e25-bd80-eacb7670d0e1 Page 1 of 1