Gambling Goblin: Malicious Apache Modules Hijack Brazilian Government Sites for Gambling Redirects and SEO Fraud
Check Point Research links the Chinese-speaking cluster Gambling Goblin to malicious Apache reverse-proxy modules installed on compromised Brazilian government and education web servers since mid-2025, which redirect selected visitors to gambling and fake…
Check Point Research is tracking Gambling Goblin, a Chinese-speaking cluster that since mid-2025 has compromised Brazilian government and education web servers and installed custom malicious Apache modules acting as reverse proxies. The modules route selected visitors to gambling and sports-betting phishing pages impersonating Google Play, the Microsoft Store, and Amazon, while stripping the sites' existing Content-Security-Policy headers and replacing them with permissive settings; Check Point assesses this is likely large-scale SEO manipulation. The broader Linux toolkit includes the DownPro downloader, the AlphaAgent and oRAT backdoors, the 3snake-based PasswordHarvester credential stealer, and an SSH brute-forcer, with phishing operations extending to Vietnamese, Spanish, and English pages. Victims spanned federal, state, and municipal government, a state-owned utility, and news and healthcare sites. Check Point linked the cluster to Earth Berberoka, a Chinese-speaking group Trend Micro documented in 2022 targeting gambling sites in Asia; Infosecurity Magazine described the attribution as medium-to-high confidence, citing shared oRAT tooling, Chinese-language artifacts, and domains mimicking trusted technology brands. Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io. Separately, ANY.RUN found at least 20 .gov.br portals serving as a delivery chain in the related PhantomEnigma campaign, and Hunt.io found more than 630,000 URLs on hijacked gov.br subdomains serving keyword-stuffed pages to Googlebot.
- Check Point Research tracks Gambling Goblin, a Chinese-speaking cluster installing malicious Apache reverse-proxy modules on compromised Brazilian government and education web servers since mid-2025.
- The modules send selected visitors to attacker-controlled gambling and sports-betting phishing pages impersonating Google Play, the Microsoft Store, and Amazon (Infosecurity Magazine); The Hacker News describes the redirects as going to…
- The modules strip the sites' existing Content-Security-Policy headers and replace them with permissive settings, activity Check Point assesses is likely intended for large-scale SEO manipulation.
- The Linux toolkit includes the DownPro downloader, AlphaAgent and oRAT backdoors, the 3snake-based PasswordHarvester credential stealer, and an SSH brute-forcer.
- Phishing operations extended to Vietnamese, Spanish, and English pages, per Infosecurity Magazine.
- Victims spanned federal, state, and municipal government, a state-owned utility, and news and healthcare sites, per Infosecurity Magazine.
- Check Point linked Gambling Goblin to Earth Berberoka, which Trend Micro documented in 2022 targeting gambling sites in Asia; Infosecurity Magazine rates the attribution medium-to-high confidence, citing shared oRAT tooling,…
- Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io.
Coverage timelineoldest first · each row is one article
- · 14d agoMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News· 48
Check Point links Gambling Goblin, a Chinese-speaking cluster, to malicious Apache modules hijacking Brazilian government servers to promote betting sites.