Skip to main content
Return to TrendAI™ Deep Research
APTs Cyber crime

Exposing Earth Berberoka: A Multiplatform APT Campaign Targeting Online Gambling Sites

Our research uncovers the tools and techniques used by Earth Berberoka across different platforms to target online gambling sites.

APTs Cyber crime Targeted attacks Malware Media & entertainment Technology, media, & communications

We have discovered an advanced persistent threat (APT) group that primarily targets online gambling sites. This group, which we have dubbed Earth Berberoka (aka GamblingPuppet), uses old yet upgraded malware families that have been attributed to Chinese-speaking actors, including PlugX and Gh0st RAT. It also uses a brand-new multistage malware family, which we have dubbed PuppetLoader. The malware families used by Earth Berberoka are multiplatform, targeting the Windows, Linux, and macOS operating systems.

Targets

Based on our analysis, we believe that Earth Berberoka’s primary targets have been gambling websites in China. However, we also have evidence that the group has targeted nongambling sites, including one education-related government institution, two IT services companies, and one electronics manufacturing company. 

From Dec. 12, 2020, to April 29, 2022, we logged 15 downloads of a fake Adobe Flash Player installer in China, eight redirects from certain websites to the malicious Adobe Flash Player website (five from a legitimate news website in the US and three from an unknown website, two of which were from Hong Kong and one from Malaysia), and one PlugX DLL detection in Taiwan. 

Figure 1. Earth Berberoka telemetry hits from Dec. 12, 2020, to April 29, 2022

Earth Berberoka’s keyloggers generated logs that indicated that a Malaysia-based hosting provider was being compromised. A similar log file found in the wild contained an IP address belonging to a Chinese gambling website. A third log file contained the login page URL of another Chinese gambling website. These last two files strengthened our belief that the gambling industry had indeed been a major target of Earth Berberoka. 

Hints of Earth Berberoka’s targeted countries can be found in one of the backdoored applications that the group has used. The first hint is that the registration process is restricted to the US, Canada, and countries in Asia, including China, Hong Kong, Macao, Taiwan, the Philippines, Japan, and South Korea. Another hint resides in the decrypted configuration files from samples of Xnote and HelloBot, two malware families that the group has used to target the Linux platform. Based on our analysis, these configuration files contain some words that might relate to gambling companies.

Infection vectors

Earth Berberoka has used different infection vectors in the delivery of some of the malware families that it has employed in its campaign. These include a supposedly secure chat app named MiMi, a fake cryptocurrency exchange app, and a website for a malicious Adobe Flash Player installer.

Backdoored ‘secret’ chat app

Earth Berberoka uses a backdoored chat app called MiMi. Based on its website, which is written in Chinese, MiMi is a “secret” chat app — “mì mì ()” means “secret” — that is available for both Windows and macOS. MiMi contains an embedded malware that is downloaded and run in the background upon launch of the MiMi chat app executable on a victim’s machine. It should be noted that although the chat app contains malware, we did not analyze the app itself as it appeared to be a legitimately functioning chat app.

The launched MiMi chat user interface shown while another executable with malware is running in the background
Figure 2. The launched MiMi chat user interface shown while another executable with malware is running in the background

MiMi prompts new users to register with either a phone number or an email address. The choices of countries that the app supports are limited to the US, Canada, and a number of Asian countries, based on the phone number prefixes available in the registration drop-down menu. This supports our belief that gambling websites catering to Asian countries are the primary targets of Earth Berberoka’s campaign.

The MiMi chat app registration screen, with the mobile number registration field featuring a drop-down menu with mostly Asian phone number prefixes
Figure 3. The MiMi chat app registration screen, with the mobile number registration field featuring a drop-down menu with mostly Asian phone number prefixes

Our analysis uncovered that the macOS version of MiMi loads two malicious executables that are both samples of the oRAT malware, while the Windows version loads a recent 64-bit version of the PlugX malware. We discuss the technical details of both malware families in relation to their use by Earth Berberoka in a blog entry.

Earth Berberoka’s infection chain via the MiMi chat app’s website
Figure 4. Earth Berberoka’s infection chain via the MiMi chat app’s website

Fake cryptocurrency exchange app

Earth Berberoka also uses a fake BitGet app for macOS. BitGet is a Singapore-based cryptocurrency exchange platform.The preinstall script of the fraudulent BitGet app downloads and executes the oRAT malware.

The preinstall script of the fake BitGet app
Figure 5. The preinstall script of the fake BitGet app

Fake website delivering backdoored Adobe Flash Player installer

Earth Berberoka exploits a persistent cross-site scripting (XSS) vulnerability in a legitimate website to execute JavaScript code hosted in a third-party server. The injected code calls a PHP script named xss.php, verifies that the victim is running Windows, and sets a cookie to ensure that the code will not be executed more than once. A pop-up with a message in Chinese then appears, stating that the version of Adobe Flash Player is too old to display the content, and redirects the victim to a website offering a supposedly updated version of Adobe Flash Player.

Our investigation yielded multiple websites that promise victims a free updated version of Adobe Flash Player but in fact tricks them into downloading malware. Although Adobe has not supported Flash Player since Dec. 31, 2020, and all major websites have disabled Flash plug-ins, we learned that Adobe allows a third-party editor to deliver a version of Flash Player in mainland China through the flash.cn website.

Earth Berberoka’s infection chain via a fake website offering a backdoored Adobe Flash Player installer
Figure 6. Earth Berberoka’s infection chain via a fake website offering a backdoored Adobe Flash Player installer

Consistent with the other fake websites connected to this campaign, this malicious Flash website is also written in Chinese, suggesting that Earth Berberoka primarily targets Chinese-speaking individuals.

A fake Chinese Adobe Flash Player website
Figure 7. A fake Chinese Adobe Flash Player website

According to our telemetry, Earth Berberoka has abused two websites for its infection chain involving its backdoored Adobe Flash Player installer. One is a news website aimed at the Chinese community of a large US city, and the other is an unknown website that was offline and had no domain name at the time of our investigation.

Thwarting Earth Berberoka’s attacks

Our investigation of Earth Berberoka’s tools and infrastructure shows that this APT group has a lot of manpower and resources at its disposal. The group has used old yet upgraded malware along with malware families that it seems to have built specifically for this campaign. And as the online gambling market continues to grow, we can expect more attacks from Earth Berberoka and other APT groups that target this financially lucrative industry. 

Our research paper “Operation Earth Berberoka: An Analysis of a Multivector and Multiplatform APT Campaign Targeting Online Gambling Sites” provides an in-depth technical analysis of Earth Berberoka’s tools, infrastructure, and potential attribution. This can help arm operators and users of gambling websites with the information that they need to avoid falling victim to Earth Berberoka’s attacks.