ZeroHour
The Hacker Newspublished ()ingested [email protected] (The Hacker News)

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

mediumThreat actor exploited in the wildimportance 48
AI summary · glm-5.3-flash

Check Point links Gambling Goblin, a Chinese-speaking cluster, to malicious Apache modules hijacking Brazilian government servers to promote betting sites.

Check Point Research tracks Gambling Goblin, a Chinese-speaking cluster, installing malicious Apache reverse-proxy modules on compromised Brazilian government and education web servers since mid-2025. The modules divert visitors to gambling and fake app-store pages while stripping the site's security headers, likely for large-scale SEO manipulation. The group's Linux arsenal includes DownPro, AlphaAgent, oRAT, a 3snake-based credential stealer, and SSH brute-forcing tools, and it is tied to Trend Micro's Earth Berberoka. Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io.

  • Malicious Apache modules reverse-proxy visitors from hijacked government domains to gambling and fake app-store pages.
  • Linux toolset includes DownPro, AlphaAgent, oRAT, a 3snake credential stealer, and an SSH brute-forcer.
  • ANY.RUN found at least 20 .gov.br portals serving as a delivery chain in the related PhantomEnigma campaign.
  • Hunt.io found more than 630,000 URLs on hijacked gov.br subdomains serving keyword-stuffed pages to Googlebot.
  • Cluster linked to Earth Berberoka, documented by Trend Micro in 2022 targeting gambling sites in Asia.

Indicators of compromiseAll →

TypeIndicatorContext
domaingov.brt it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages
domainhunt.ioreverse-proxy technique on IIS servers in September 2025 . Hunt.io said in July 2025 that it had found more than 630,000 URLs
domainregistro.brthorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry. Check Point did not say whether
Full article773 words · extracted from thehackernews.com · click to collapse

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.

Check Point Research said it has tracked the campaign since mid-2025.

The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site's own security headers are stripped, allowing the injected content to run freely.

Those pages pose as trusted app stores including Google Play, Microsoft Store, and Amazon, and push online gambling and sports betting behind that facade.

Check Point said the likely goal is search engine optimization (SEO) manipulation at scale, with compromised high-reputation domains, many of them Brazilian government sites, chained together to inflate search rankings.

ANY.RUN reported in July that at least 20 .gov.br portals belonging to Brazilian municipalities and police forces had been used to distribute malware in a campaign it tracks as PhantomEnigma .

"These government systems are part of the delivery chain, not confirmed campaign targets," ANY.RUN said in a report published July 16.

Compromised .gov.br and .jus.br hosts should be handled separately from attacker-controlled infrastructure, ANY.RUN said, because blocking them broadly would disrupt access to government resources.

Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023, and authorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry.

Check Point did not say whether the betting sites promoted through the compromised servers hold that authorization.

Once on a host, Check Point said the group deploys the following tools -

DownPro , a custom downloader

AlphaAgent , a modular backdoor

oRAT , a remote access trojan (RAT)

A 3snake-based credential stealer

An SSH brute-forcer

A plugin-driven reconnaissance agent

The public version of 3snake attaches ptrace to newly spawned sshd and sudo processes and extracts strings related to password-based authentication. Its documentation states that the tool targets rooted servers.

The Hacker News reviewed the 3snake source on GitHub on September 2, 2026, and confirmed both. The credentials used to administer a compromised server are therefore read by a component the operators control.

Check Point said it hasn't directly observed how the group obtains initial access. An exposed open directory on one of the actor's servers held an ELF binary written in Go that bundles reconnaissance and scanning plugins.

The material published so far includes no count of compromised servers and no module filenames, paths, or hashes that would let administrators check the modules loaded into their own Apache instances.

Parallel phishing networks localized in Vietnamese, Spanish, and English were also identified, along with infrastructure that generates new domains daily. Because the pages already mimic app-download destinations, Check Point said the operators sit "one step from pushing malware straight to victims."

The published summary names no affected organization and does not say whether the compromised servers have been cleaned.

Check Point tied the cluster to Earth Berberoka, an actor Trend Micro documented in 2022 as targeting gambling websites across Asia using malware families historically attributed to Chinese-speaking individuals.

Xnote, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia.

oRAT, one of the Linux tools in that arsenal, was documented by Trend Micro in April 2022 as Earth Berberoka malware, in Windows and macOS samples both flagged as version 0.5.1. The Hacker News confirmed that provenance against Trend Micro's research on September 2, 2026.

ESET documented at least 65 Windows servers , mainly in Brazil, Thailand, and Vietnam, compromised in June 2025 by GhostRedirector, an actor it assessed with medium confidence as China-aligned, which installed a native Internet Information Services (IIS) module called Gamshen.

"GhostRedirector has developed a malicious native IIS module, Gamshen, that can perform SEO fraud; we believe its purpose is to artificially promote various gambling websites," ESET said.

Gamshen altered the server's response only when the request came from Googlebot, leaving ordinary visitors with the page they asked for.

Palo Alto Networks Unit 42 documented the same reverse-proxy technique on IIS servers in September 2025 .

Hunt.io said in July 2025 that it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages to Googlebot while redirecting real users to betting sites.

The company redacted certain indicators in coordination with Brazil's government incident response team, CTIR, while that investigation continued.

"The goal was not to break into systems. It was to control visibility," Hunt.io said.

Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/malicious-apache-modules-hijack.html