Back Infosecurity-Magazine Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
A Chinese-speaking cybercrime cluster has turned compromised Brazilian government and education websites into infrastructure for a sustained SEO fraud campaign operating since mid-2025.
Check Point Research (CPR) dubbed the group Gambling Goblin and assessed with medium-to-high confidence that it is connected to Earth Berberoka, a Chinese-speaking cluster documented by Trend Micro in 2022 as targeting gambling platforms serving Chinese-speaking users.
The research , published on September 2, said the overlaps covered tooling, operator artifacts and infrastructure, including the use of oRAT, Chinese-language strings and domains resembling trusted technology brands.
CPR described the campaign as a shift from Brazil's -grown banking trojans to a foreign operator, drawn by one of the world's fastest-growing online betting markets.
Malicious Apache Modules Turn Trusted Sites into Proxies
The attackers installed custom Apache modules that acted as a reverse proxy, quietly routing selected visitors from compromised sites to attacker-controlled phishing pages.
CPR said the modules targeted specific URL paths and could strip existing Content-Security-Policy headers, replacing them with permissive settings that allowed external and dynamically generated scripts to run.
An installer compiled each module on the victim server, then deleted the source and timestomped the resulting file to match legitimate Apache modules.
The phishing pages impersonated destinations including Google Play, the Microsoft Store and Amazon. They were localized for Brazilian users and online gambling and sports betting.
The compromised organizations spanned federal, state and municipal government, including a ministry, a national public agency, a state legislative assembly, courts of accounts and a state-owned utility. Municipal administrations made up the largest .
The campaign also affected commercial Brazilian sites such as local news organizations, healthcare providers and business associations.
A Large Linux Toolkit Supports the Operation
The web-server activity sat alongside a broader Linux malware toolkit that CPR said included the DownPro downloader, backdoors including AlphaAgent and oRAT, the 3snake-based PasswordHarvester credential stealer and an SSH brute-forcer. Most were wrapped in packing and virtualization layers to slow analysis.
The researchers also found a reconnaissance agent that used tools such as httpx, naabu, Nuclei and subfinder, to map internet-facing infrastructure and identify services running on potential targets.
AlphaAgent supported remote command execution (RCE), file transfers, tunneling and host discovery, while oRAT provided remote administration. CPR identified an AI plugin execution path in a newer AlphaAgent build, although it said the sample did not reveal what the plugin did.
The infrastructure extended beyond Brazil. CPR found phishing pages localized in Vietnamese, Spanish and English, alongside systems generating fresh domains daily.
The researchers warned the setup created a potential path to direct malware distribution because the phishing infrastructure already imitated legitimate app stores. CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.
Trojanized Android App Fuels New Wave of NFC Fraud News 21 April 2026
Trojanized Android App Fuels New Wave of NFC Fraud
PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time News 12 March 2026
PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time
Novel Banking Trojan 'PixPirate' Targets Brazil News 6 February 2023
Novel Banking Trojan 'PixPirate' Targets Brazil
BTMOB Android RAT Spreads Through No-Code Builder Tooling News 26 May 2026
BTMOB Android RAT Spreads Through No-Code Builder Tooling
New Grandoreiro Malware Variant Targets Spain News 23 October 2023
New Grandoreiro Malware Variant Targets Spain
What’s Hot on Infosecurity Magazine?
Cybersecurity Job Ads Requiring AI Skills Double
Healthcare Giant McKesson Investigates Data Breach Incident
Average Cyber Insurance Losses Increase Despite Fewer Claims
Manchester Airports Group Hit by Cyber Incident
Attackers Steal METR API Key and Burn $600,000 in AI Credits
65% of Enterprises Have Seen AI Agents Act Out of Scope
DDoS Attack Hits Norwegian Government Services
Manchester Airports Group Hit by Cyber Incident
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
Average Cyber Insurance Losses Increase Despite Fewer Claims
Agentic AI will Supercharge Cyber Threats. But Not in the Way You Think
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How To Enhance Security Operations with AI-Powered Defenses
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
How to Manage Your Risks and Protect Your Financial Data
Dispelling the Myths of Defense-Grade Cybersecurity
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
