AlphaAgent is a modular Go-based Linux backdoor associated with the Chinese-speaking Gambling Goblin cybercrime cluster, which has been linked with medium-to-high confidence to Earth Berberoka. It has been deployed as post-compromise tooling against Brazilian government, educational, commercial, healthcare, and media web-server environments in a gambling-focused SEO-fraud and phishing operation active since mid-2025. AlphaAgent provides encrypted remote command execution, interactive shell access, file transfer, tunneling, proxying, and host discovery. It collects SSH keys and shell-history data, enabling credential access and follow-on movement through compromised environments. The malware supports encrypted gRPC-over-HTTPS communications, DNS tunneling, and an HTTP communication variant; it encrypts task data and can emulate browser network fingerprints and cloud-service themes to blend command-and-control traffic with legitimate activity. AlphaAgent also incorporates process and service-name masquerading, geofencing, sandbox-aware host inventory, and optional process hiding to reduce detection. Some builds contain an AI-plugin execution path, although its operational function has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Its toolkit includes DownPro, AlphaAgent, oRAT RAT, 3snake credential stealer, SSH brute-forcer, and reconnaissance tools.”
“AlphaAgent can run commands, move files, create tunnels, collect SSH keys and shell history, and hide under system-service names.”
20 distinct techniques documented for this family, organized by ATT&CK tactic.
AlphaAgent can install an embedded rootkit kernel module; other builds carry a component that hides processes and network connections at kernel level.
“Several tools use disguises, encryption, and memory-only unpacking.”
AlphaAgent can... hide under system-service names. oRAT can establish persistence through a service that mimics a legitimate firewall component.
“The malware can be disguised as a legitimate system service to reduce suspicion. oRAT similarly establishes persistence through a service designed to resemble a normal firewall-related component.”
AlphaAgent sets HISTFILE=/dev/null before executing remote shell commands.
AlphaAgent inventories active connections and interface addresses; info.sh gathers listening TCP ports and ARP neighbors.
AlphaAgent primarily uses gRPC over HTTPS; oRAT multiplexes HTTP requests over TCP, TLS/TCP, or QUIC/UDP sessions.
An AlphaAgent variant encrypts and Base32-encodes jobs, splits them across DNS labels, and exchanges them as TXT-style traffic on port 53.
AlphaAgent bundles a SOCKS5 proxy, yamux multiplexer, Ligolo-style relay, and a relay listener that forwards traffic upstream.
“After gaining access, the attackers can deploy additional tools through DownPro, a loader capable of retrieving payloads such as the ChUser backdoor, AlphaAgent and oRAT.”
“AlphaAgent supported remote command execution (RCE), file transfers, tunneling and host discovery, while oRAT provided remote administration.”
AlphaAgent bootstraps through public DoH providers such as Cloudflare and Google to resolve its server.
89 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named component of Gambling Goblin's toolkit used in the campaign targeting Brazilian government and educational organizations.
Remote-access malware that executes commands, transfers files, establishes tunnels, and collects SSH keys and shell-history data. It can masquerade as a legitimate system service.
A Linux remote-access backdoor that executes commands, transfers files, establishes tunnels, steals SSH keys and shell history, and disguises itself as a system service.
A Linux remote-access backdoor that supports command execution, file operations, tunneling, SSH private-key and shell-history collection, and masquerading as system services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.