Earth Berberoka
Also reported as GamblingPuppet. Linked to China by three sources.
Reports per quarter
CVEs named in reports
- CVE-2017-15944 KEV
- CVE-2018-1207
- CVE-2019-17100
- CVE-2019-8526 KEV
- CVE-2020-10189 KEV
- CVE-2020-14882 KEV
- CVE-2021-1879 KEV
- CVE-2021-21166 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26868
Show all 31 CVEs Show fewer
- CVE-2021-27065 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-30869 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-21587 KEV ransomware
- CVE-2022-26134 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2024-30051 KEV ransomware
- CVE-2024-4577 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor DCRat (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HyperBro (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor AsyncRAT (Malware Family)
Show all 65 reports Show fewer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Mac Malware of 2022
-
DiceyF deploys GamePlayerFramework in online casino development studio
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DiceyF deploys GamePlayerFramework in online casino development studio
-
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
-
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IOCs for Earth Berberoka
-
IOCs for Earth Berberoka - MacOS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IOCs for Earth Berberoka - MacOS
-
New APT Group Earth Berberoka Targets Gambling Websites With Old and New Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New APT Group Earth Berberoka Targets Gambling Websites With Old and New Malware
-
IOCs for Earth Berberoka - Windows
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IOCs for Earth Berberoka - Windows
-
IOCs for Earth Berberoka - Linux
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IOCs for Earth Berberoka - Linux
-
Operation Poisoned News- Hong Kong Users Targeted With Mobile Malware via Local News Links
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Poisoned News- Hong Kong Users Targeted With Mobile Malware via Local News Links
-
MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MuddyWater Resurfaces, Uses Multi-Stage Backdoor POWERSTATS V3 and New Post-Exploitation Tools
-
Account With Admin Privileges Abused to Install BitPaymer Ransomware via PsExec
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Account With Admin Privileges Abused to Install BitPaymer Ransomware via PsExec
-
Linux Users Urged to Update as a New Threat Exploits SambaCry
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Linux Users Urged to Update as a New Threat Exploits SambaCry
-
RawPOS- New Behavior Risks Identity Theft
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor RawPOS- New Behavior Risks Identity Theft
-
FastPOS Updates in Time for the Retail Sale Season
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FastPOS Updates in Time for the Retail Sale Season
-
Untangling the Ripper ATM Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Untangling the Ripper ATM Malware
-
BkSoD by Ransomware- HDDCryptor Uses Commercial Tools to Encrypt Network Shares and Lock HDDs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BkSoD by Ransomware- HDDCryptor Uses Commercial Tools to Encrypt Network Shares and Lock HDDs
-
CrypMIC Ransomware Wants to Follow CryptXXX’s Footsteps
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrypMIC Ransomware Wants to Follow CryptXXX’s Footsteps
-
After Angler- Shift in Exploit Kit Landscape and New Crypto-Ransomware Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor After Angler- Shift in Exploit Kit Landscape and New Crypto-Ransomware Activity
-
FastPOS- Quick and Easy Credit Card Theft
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FastPOS- Quick and Easy Credit Card Theft
-
What We Can Learn From the Bangladesh Central Bank Cyber Heist
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What We Can Learn From the Bangladesh Central Bank Cyber Heist
-
Chinese-language Ransomware ‘SHUJIN’ Makes An Appearance
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese-language Ransomware ‘SHUJIN’ Makes An Appearance
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Black Atlas Endangers In-Store Card Payments and SMBs Worldwide; Switches between BlackPOS and Other Tools
-
Pawn Storm Targets MH17 Investigation Team
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pawn Storm Targets MH17 Investigation Team
-
New Adobe Flash Zero-Day Used in Pawn Storm Campaign Targeting Foreign Affairs Ministries
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Adobe Flash Zero-Day Used in Pawn Storm Campaign Targeting Foreign Affairs Ministries
-
Two New PoS Malware Affecting US SMBs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Two New PoS Malware Affecting US SMBs
-
Attackers Target Organizations in Japan; Transform Local Sites into C&C Servers for EMDIVI Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attackers Target Organizations in Japan; Transform Local Sites into C&C Servers for EMDIVI Backdoor
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SIMDA- A Botnet Takedown
-
NewPosThings Has New PoS Things
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NewPosThings Has New PoS Things
-
Fake Judicial Spam Leads to Backdoor with Fake Certificate Authority
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fake Judicial Spam Leads to Backdoor with Fake Certificate Authority
-
Mobile Malware Gang Steals Millions from South Korean Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mobile Malware Gang Steals Millions from South Korean Users
-
New PoS Malware Kicks off Holiday Shopping Weekend
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New PoS Malware Kicks off Holiday Shopping Weekend
-
ROVNIX Infects Systems with Password-Protected Macros
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ROVNIX Infects Systems with Password-Protected Macros
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Timeline of Sandworm Attacks
-
New BlackPOS Malware Emerges in the Wild, Targets Retail Accounts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New BlackPOS Malware Emerges in the Wild, Targets Retail Accounts
-
BIFROSE Now More Evasive Through Tor, Used for Targeted Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BIFROSE Now More Evasive Through Tor, Used for Targeted Attack
-
KIVARS With Venom- Targeted Attacks Upgrade with 64-bit “Support”
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor KIVARS With Venom- Targeted Attacks Upgrade with 64-bit “Support”
-
Sykipot Now Targeting US Civil Aviation Sector Information
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sykipot Now Targeting US Civil Aviation Sector Information
-
BKDR_RARSTONE- New RAT to Watch Out For
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE- New RAT to Watch Out For
-
Shylock Not the Lone Threat Targeting Skype
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shylock Not the Lone Threat Targeting Skype
-
Infostealer Dexter Targets Checkout Systems
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Infostealer Dexter Targets Checkout Systems
-
What’s the Fuss with WORM_VOBFUS-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What’s the Fuss with WORM_VOBFUS-
-
JACKSBOT Has Some Dirty Tricks up Its Sleeves
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor JACKSBOT Has Some Dirty Tricks up Its Sleeves
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ZeuS Gets Another Update
-
SASFIS Malware Uses a New Trick
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SASFIS Malware Uses a New Trick
Newest first. Details opens the report in Explore.