Illuminating
Insights
What a security investigation reveals about today’s gaming cyber threats
When unusual activity or anomalies are detected in a company’s IT infrastructure, this may suggest a potential problem. In such cases, a team of security professionals analyze the available evidence to determine whether unauthorized access has occurred, identify the techniques employed, and assess the impact for the organization.
A recent investigation by the Bulletproof security team presents an overview of the mechanisms behind modern gaming cyberattacks, and measures that organizations can use to strengthen their resilience against these threats.

A wide-ranging investigation typically covers the following areas:
These methods aim to comprehensively identify all indicators, such as potential backdoors and techniques for data exfiltration.
Security investigators use a blend of automated tools and hands-on investigation to:

During our investigation of a casino gaming client, the digital equivalent of a break-in was confirmed. Here’s what our cybersecurity team found:

The investigation flagged five key signs that an attack had taken place:
There is no definitive or conclusive attribution to a particular origin or group; however, tools such as PupyRat were observed in cyberattacks associated with Earth Berberoka (also referred to as GamblingPuppet or DiceyF). This group is believed to have links to Chinese-speaking individuals and has been active since early 2022. Their operations primarily target online gambling and casino websites, especially within China and Southeast Asia[i].
Moreover, the analysis revealed that multiple files initially encoded in ASCII presented Chinese characters when processed with Unicode encoding and the translation of these characters subsequently uncovered hidden information. This method is commonly employed to evade detection.

Responding to and recovering from a breach encompasses more than the restoration of normal operations; it presents an opportunity to strengthen organisational resilience. Our Bulletproof cybersecurity recommends:
This case isn’t unique. Cyber attackers are constantly evolving, making use of both new malware and legitimate system tools to slip past traditional defenses. While technology helps, the key to cybersecurity resilience is a culture of vigilance, regular testing, and readiness to respond quickly when (not if) anomalies are detected.
Distributed Denial of Service (DDoS) attacks can flood casino systems with overwhelming traffic, resulting in service outages that disrupt gaming operations and cause significant revenue loss, particularly during peak times. Alongside this threat, insider threats pose a serious risk, as employees or contractors with access to sensitive systems may inadvertently or deliberately compromise security, leading to data leaks. These situations illustrate several potential vulnerabilities where data may be at risk.
With the vast amount of personal and financial data casinos collect from their players with key efforts around enhancing KYC initiatives, they are prime targets for data breaches. An attack could expose sensitive information, leading to identity theft and loss of player trust.
Even when your code and systems are well-built, the threat landscape is always changing. Proactive monitoring, robust incident response plans, internal cyber awareness training, and a healthy dose of skepticism about anything unusual can make all the difference.
The online gaming and land-based gambling industry is increasingly targeted by cybercriminals. To address these risks, operators are encouraged to implement strong security protocols, invest in advanced defensive technologies, and collaborate with others in the sector to share threat intelligence in real time. Operators must remain vigilant and invest in robust cybersecurity measures to protect against these evolving threats. A proactive approach can help strengthen platform security, protect player data and funds, and maintain player confidence.
[i] Operation Earth Berberoka: An Analysis of a Multivector and Multiplatform APT Campaign Targeting Online Gambling Sites
To learn more about how GLI can help your gaming cybersecurity needs, contact your GLI representative today.
< Back to All Blogs