Earth Berberoka
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Earth Berberoka, also tracked as Earth Emperror, is associated with China‑based operations. Public reporting links the alias to a China‑linked group identified as RedEcho. The actor’s origin is assessed to be within China, though no specific organizational affiliation is disclosed. Attribution to a state nexus is suggested by the description of the group as China‑linked and by its alignment with broader Chinese cyber activity. No public indication ties the actor to a criminal consortium or mercenary structure.
The actor’s observed targeting focuses on critical infrastructure sectors, specifically the power generation and distribution network, maritime entities related to towing and port services, and associated services such as hospitals, rail transport and financial markets. Geographic focus has been noted in India, with the Mumbai region cited as the location of a significant power outage incident in October 2020. The actor’s strategic objective appears to be disruption of essential services to convey a geopolitical warning, as indicated by statements linking the campaign to China’s strategic interests in India via the Belt and Road Initiative. No evidence points to financial gain or traditional espionage as the primary motive.
Technical details associated with the actor’s operations include the use of the AXIOMATICASYMPTOTE malware family and infrastructure tied to ShadowPad servers, both of which have been reported in conjunction with the RedEcho campaign. The group's tactics show overlap with those of the known Chinese cyber group APT41/Barium, suggesting similarities in tooling and procedural approaches. Initial access vectors are not described in the available sources, so no specific phishing, exploit or credential‑theft method can be asserted. A representative operation is the coordinated intrusion against ten Indian power sector organizations and two maritime firms that preceded the widespread Mumbai power disruption, which also affected hospital systems, train services and stock‑exchange activity. This campaign is cited as the most prominent publicly reported activity attributed to the actor.
Incidents
Attributed incidents are available to members.
0 incidents