ZeroHour
Story · 1 source · 1 articlefirst updated ()

Gambling Goblin: Malicious Apache Modules Hijack Brazilian Government Sites for Gambling Redirects and SEO Fraud

mediumThreat actorexploited in the wildimportance 64
What's new: Initial merged summary; no prior version exists. Both source reports (The Hacker News and Infosecurity Magazine, both published 2026-09-02) cover the same Check Point Research findings, so this merge establishes the story baseline. Source-level differences were reconciled toward the more specific Infosecurity Magazine details, e.g., stripping CSP headers specifically (vs. generic 'security…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Check Point Research links the Chinese-speaking cluster Gambling Goblin to malicious Apache reverse-proxy modules installed on compromised Brazilian government and education web servers since mid-2025, which redirect selected visitors to gambling and fake…

Check Point Research is tracking Gambling Goblin, a Chinese-speaking cluster that since mid-2025 has compromised Brazilian government and education web servers and installed custom malicious Apache modules acting as reverse proxies. The modules route selected visitors to gambling and sports-betting phishing pages impersonating Google Play, the Microsoft Store, and Amazon, while stripping the sites' existing Content-Security-Policy headers and replacing them with permissive settings; Check Point assesses this is likely large-scale SEO manipulation. The broader Linux toolkit includes the DownPro downloader, the AlphaAgent and oRAT backdoors, the 3snake-based PasswordHarvester credential stealer, and an SSH brute-forcer, with phishing operations extending to Vietnamese, Spanish, and English pages. Victims spanned federal, state, and municipal government, a state-owned utility, and news and healthcare sites. Check Point linked the cluster to Earth Berberoka, a Chinese-speaking group Trend Micro documented in 2022 targeting gambling sites in Asia; Infosecurity Magazine described the attribution as medium-to-high confidence, citing shared oRAT tooling, Chinese-language artifacts, and domains mimicking trusted technology brands. Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io. Separately, ANY.RUN found at least 20 .gov.br portals serving as a delivery chain in the related PhantomEnigma campaign, and Hunt.io found more than 630,000 URLs on hijacked gov.br subdomains serving keyword-stuffed pages to Googlebot.

  • Check Point Research tracks Gambling Goblin, a Chinese-speaking cluster installing malicious Apache reverse-proxy modules on compromised Brazilian government and education web servers since mid-2025.
  • The modules send selected visitors to attacker-controlled gambling and sports-betting phishing pages impersonating Google Play, the Microsoft Store, and Amazon (Infosecurity Magazine); The Hacker News describes the redirects as going to…
  • The modules strip the sites' existing Content-Security-Policy headers and replace them with permissive settings, activity Check Point assesses is likely intended for large-scale SEO manipulation.
  • The Linux toolkit includes the DownPro downloader, AlphaAgent and oRAT backdoors, the 3snake-based PasswordHarvester credential stealer, and an SSH brute-forcer.
  • Phishing operations extended to Vietnamese, Spanish, and English pages, per Infosecurity Magazine.
  • Victims spanned federal, state, and municipal government, a state-owned utility, and news and healthcare sites, per Infosecurity Magazine.
  • Check Point linked Gambling Goblin to Earth Berberoka, which Trend Micro documented in 2022 targeting gambling sites in Asia; Infosecurity Magazine rates the attribution medium-to-high confidence, citing shared oRAT tooling,…
  • Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io.

Coverage timeline

  1. · 14d ago
    The Hacker News· 48
    Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

    Check Point links Gambling Goblin, a Chinese-speaking cluster, to malicious Apache modules hijacking Brazilian government servers to promote betting sites.