cam-agent is a Go-based ELF reconnaissance utility used by the Chinese-speaking Gambling Goblin cybercrime cluster. It maps internet-facing infrastructure and identifies potential targets by bundling reconnaissance and scanning functionality, including web probing, port scanning, vulnerability scanning, subdomain discovery, and technology identification. It has been identified on exposed infrastructure associated with campaigns targeting Brazilian government and educational organizations. Gambling Goblin has been linked with medium-to-high confidence to the Earth Berberoka cluster.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Check Point researchers also identified a scanning component called cam-agent on exposed systems, which is used to gather information about internet-facing infrastructure and identify potential targets.”
“Researchers did not directly observe the initial break-in, but uncovered a scanning agent called cam-agent on exposed infrastructure. It uses reconnaissance tools to map internet-facing systems.”
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Researchers... uncovered a scanning agent called cam-agent on exposed infrastructure. It uses reconnaissance tools to map internet-facing systems.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A scanning component used to enumerate internet-facing infrastructure and identify prospective targets.
A reconnaissance and scanning agent used to map internet-facing systems and identify trusted web properties for compromise and abuse.
A scanning and reconnaissance agent used to map internet-facing systems and identify trusted web properties suitable for compromise and abuse.
A Go-based attack-surface mapping and reconnaissance agent that communicates over authenticated gRPC and orchestrates plugins for port scanning, web probing, subdomain enumeration, fingerprinting, and template-based vulnerability checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.