Researchers reported that the newly identified APT group Earth Berberoka has targeted gambling websites using a mix of older tools and a cross-platform oRAT remote access trojan, including a macOS variant written in Go. The campaign used a fake Bitget application delivered as an unsigned disk image, with a package installer that relied on a preinstall script to drop and launch the malware from /tmp, indicating an effort to blend social engineering with lightweight macOS tradecraft.
Analysis of the macOS sample showed a UPX-packed Go binary with an encrypted configuration blob appended to the file and decrypted at runtime to recover command-and-control settings. The malware supports multiple communication modes, including TCP, STCP, and SUDP, and uses smux and QUIC for networking while beaconing to its C2 every five seconds. Once active, oRAT can transfer files, provide shell access, proxy traffic, scan ports, capture screenshots, and delete itself, underscoring a capable espionage toolset despite the comparatively unsophisticated delivery chain.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
SentinelOne published analysis of an unsigned macOS variant of the Go-based oRAT malware linked to the gambling-site targeting campaign. The report described delivery via a fake Bitget disk image and detailed the malware's installer, payload, configuration decryption, networking, and RAT capabilities.
Trend Micro reported a newly identified APT group, Earth Berberoka, targeting gambling websites and using both old and new malware in its operations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.