Skip to content
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

Infosecurity-Magazine September 2, 2026

A Chinese-speaking cybercrime cluster has turned compromised Brazilian government and education websites into infrastructure for a sustained SEO fraud campaign operating since mid-2025.

Check Point Research (CPR) dubbed the group Gambling Goblin and assessed with medium-to-high confidence that it is connected to Earth Berberoka, a Chinese-speaking cluster documented by Trend Micro in 2022 as targeting gambling platforms serving Chinese-speaking users.

The research , published on September 2, said the overlaps covered tooling, operator artifacts and infrastructure, including the use of oRAT, Chinese-language strings and domains resembling trusted technology brands.

CPR described the campaign as a shift from Brazil's -grown banking trojans to a foreign operator, drawn by one of the world's fastest-growing online betting markets.

Malicious Apache Modules Turn Trusted Sites into Proxies

The attackers installed custom Apache modules that acted as a reverse proxy, quietly routing selected visitors from compromised sites to attacker-controlled phishing pages.

CPR said the modules targeted specific URL paths and could strip existing Content-Security-Policy headers, replacing them with permissive settings that allowed external and dynamically generated scripts to run.

An installer compiled each module on the victim server, then deleted the source and timestomped the resulting file to match legitimate Apache modules.

The phishing pages impersonated destinations including Google Play, the Microsoft Store and Amazon. They were localized for Brazilian users and online gambling and sports betting.

The compromised organizations spanned federal, state and municipal government, including a ministry, a national public agency, a state legislative assembly, courts of accounts and a state-owned utility. Municipal administrations made up the largest .

The campaign also affected commercial Brazilian sites such as local news organizations, healthcare providers and business associations.

A Large Linux Toolkit Supports the Operation

The web-server activity sat alongside a broader Linux malware toolkit that CPR said included the DownPro downloader, backdoors including AlphaAgent and oRAT, the 3snake-based PasswordHarvester credential stealer and an SSH brute-forcer. Most were wrapped in packing and virtualization layers to slow analysis.

The researchers also found a reconnaissance agent that used tools such as httpx, naabu, Nuclei and subfinder, to map internet-facing infrastructure and identify services running on potential targets.

AlphaAgent supported remote command execution (RCE), file transfers, tunneling and host discovery, while oRAT provided remote administration. CPR identified an AI plugin execution path in a newer AlphaAgent build, although it said the sample did not reveal what the plugin did.

The infrastructure extended beyond Brazil. CPR found phishing pages localized in Vietnamese, Spanish and English, alongside systems generating fresh domains daily.

The researchers warned the setup created a potential path to direct malware distribution because the phishing infrastructure already imitated legitimate app stores. CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.

Trojanized Android App Fuels New Wave of NFC Fraud News 21 April 2026

Trojanized Android App Fuels New Wave of NFC Fraud

PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time News 12 March 2026

PixRevolution Malware Hijacks Brazil's PIX Transfers in Real Time

Novel Banking Trojan 'PixPirate' Targets Brazil News 6 February 2023

Novel Banking Trojan 'PixPirate' Targets Brazil

BTMOB Android RAT Spreads Through No-Code Builder Tooling News 26 May 2026

BTMOB Android RAT Spreads Through No-Code Builder Tooling

New Grandoreiro Malware Variant Targets Spain News 23 October 2023

New Grandoreiro Malware Variant Targets Spain

What’s Hot on Infosecurity Magazine?

Cybersecurity Job Ads Requiring AI Skills Double

Healthcare Giant McKesson Investigates Data Breach Incident

Average Cyber Insurance Losses Increase Despite Fewer Claims

Manchester Airports Group Hit by Cyber Incident

Attackers Steal METR API Key and Burn $600,000 in AI Credits

65% of Enterprises Have Seen AI Agents Act Out of Scope

DDoS Attack Hits Norwegian Government Services

Manchester Airports Group Hit by Cyber Incident

Linux Foundation Introduces TRACE Standard for AI Runtime Evidence

Average Cyber Insurance Losses Increase Despite Fewer Claims

Agentic AI will Supercharge Cyber Threats. But Not in the Way You Think

Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How To Enhance Security Operations with AI-Powered Defenses

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

How to Manage Your Risks and Protect Your Financial Data

Dispelling the Myths of Defense-Grade Cybersecurity

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust