ChUser is a simple Linux command-execution backdoor associated with the Chinese-speaking Gambling Goblin cybercrime cluster, which has been linked with medium-to-high confidence to Earth Berberoka. It is deployed as a follow-on payload by the DownPro downloader on compromised web servers, including systems targeted in gambling-promotion and search-fraud operations against Brazilian government and educational organizations. ChUser masquerades as a legitimate system utility and executes operator-supplied commands only after an activation check succeeds; activation can depend on either a remote HTTP response or a local secret-validation mechanism. Its role is to provide covert post-compromise remote command execution on Linux hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“After gaining access, the attackers can deploy additional tools through DownPro, a loader capable of retrieving payloads such as the ChUser backdoor, AlphaAgent and oRAT.”
“Once inside, the group can use DownPro to fetch further payloads, including the ChUser backdoor, a password-harvesting tool, AlphaAgent, oRAT, and an SSH credential-testing utility.”
4 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor delivered by the DownPro loader as part of the Gambling Goblin toolkit.
A backdoor associated with the campaign; the content additionally identifies password harvesting as a capability among payloads delivered by DownPro, but does not unambiguously assign that capability solely to ChUser.
A backdoor associated with the campaign’s post-compromise toolkit; the content identifies credential/password harvesting as a capability present in the retrieved toolset.
A command-execution backdoor installed as a disguised setuid helper. It supports remote HTTP-based activation or a locally supplied secret validated against a hardcoded MD5 target.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.