ZeroHour
Story · 1 source · 1 articlefirst updated ()

Gambling Goblin hijacks Brazilian government sites with malicious Apache modules in SEO-fraud and gambling-phishing campaign running since mid-2025

mediumThreat actorimportance 64
What's new: Initial merged summary: this is the first merged story on this topic. Coverage dated 2026-09-02 introduces Check Point's attribution of the Gambling Goblin Apache-module campaign against Brazilian government sites, plus corroborating industry observations from ESET (GhostRedirector), Palo Alto Networks Unit 42, Hunt.io, and ANY.RUN (PhantomEnigma).
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Check Point Research links a Chinese-speaking cluster, dubbed Gambling Goblin, to a campaign since mid-2025 that compromised Brazilian government and education web servers by installing malicious Apache reverse-proxy modules, silently diverting selected…

Check Point Research tracks a sustained campaign since mid-2025 against Brazilian government and educational organizations by Gambling Goblin, a Chinese-speaking cybercrime cluster linked with medium-to-high confidence (per Infosecurity Magazine) to Earth Berberoka, a group Trend Micro documented in 2022 targeting gambling sites in Asia. Attribution rests on shared oRAT tooling, Chinese-language artifacts, and domains mimicking trusted technology brands. Attackers compile and install custom malicious Apache modules on compromised servers that act as stealthy reverse proxies, silently diverting selected visitors to gambling and sports-betting phishing pages impersonating Google Play, the Microsoft Store, and Amazon, chaining compromised high-reputation domains to inflate search rankings. The modules strip the sites' security headers; Infosecurity Magazine reports Content-Security-Policy headers were stripped and replaced with permissive settings, allowing injected content to run freely. The group's Linux toolkit includes the DownPro downloader, the AlphaAgent backdoor with RCE, the oRAT backdoor, a 3snake-based credential stealer (named PasswordHarvester by Infosecurity), SSH brute-forcers, and cam-agent, a Go-based reconnaissance agent using httpx, nuclei, naabu, and subfinder modules. Parallel phishing networks localized for Vietnamese, Spanish, and English victims use daily fresh domains, indicating a scaling model built for export to new regions. Phishing pages sit one configuration change away from direct malware delivery, a latent escalation risk. Victims spanned federal, state, and municipal government, a state-owned utility, plus news and healthcare sites. Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io; ANY.RUN found at least 20 .gov.br portals serving as a delivery chain in the related PhantomEnigma campaign, and Hunt.io found more than 630,000 URLs on hijacked gov.br subdomains serving keyword-stuffed pages to Googlebot.

  • Campaign ongoing since mid-2025 against Brazilian government and educational organizations (Check Point Research, 2026-09-02).
  • Check Point dubbed the cluster Gambling Goblin and linked it with medium-to-high confidence to Earth Berberoka, which Trend Micro documented in 2022 targeting gambling sites in Asia.
  • Attribution links: shared oRAT tooling, Chinese-language artifacts, and domains mimicking trusted technology brands.
  • Custom Apache modules installed on compromised servers act as stealthy reverse proxies, silently diverting selected visitors to attacker-controlled pages.
  • Diverted visitors reach gambling and sports-betting phishing pages impersonating Google Play, the Microsoft Store, and Amazon; compromised high-reputation domains are chained to inflate search rankings.
  • Modules strip the sites' security headers; Infosecurity Magazine reports CSP headers were stripped and replaced with permissive settings.
  • Linux toolkit: DownPro downloader, AlphaAgent backdoor with RCE, oRAT backdoor, a 3snake-based credential stealer (identified by Infosecurity as PasswordHarvester), SSH brute-forcers, and cam-agent, a Go-based reconnaissance agent using…
  • Phishing pages sit one configuration change away from direct malware delivery, a latent escalation risk (Check Point).

Coverage timeline

  1. · 13d ago
    Check Point Research· 55
    Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

    Check Point identifies Chinese-speaking group Gambling Goblin hijacking Brazilian government domains via malicious Apache modules for SEO-manipulated gambling phishing.