Infosecurity-Magazine
Gambling Goblin Targets Brazilian Government Sites for SEO Fraud
Article Content
A Chinese-speaking cybercrime group, dubbed Gambling Goblin, has been targeting Brazilian government and educational institutions since mid-2025. This group is connected to the previously documented Earth Berberoka and is using compromised web servers to install malicious Apache modules. These modules reverse-proxy visitors to phishing pages masquerading as trusted app stores, promoting online gambling and sports betting. The operation has leveraged a large-scale SEO manipulation strategy, chaining together high-reputation domains to inflate traffic and rankings. The attackers deploy a broad Linux toolkit that includes custom tools such as DownPro, AlphaAgent, and oRAT, which are heavily obfuscated to evade detection. The campaign extends beyond Brazil, with parallel phishing networks identified in multiple languages. The operation poses a significant risk as it could easily pivot to direct malware delivery. Check Point Research has tracked this activity closely, highlighting the shift from domestic threats to foreign operators exploiting Brazil's growing online betting market.
Key Points: • Gambling Goblin targets Brazilian government and educational sites since mid-2025. • Malicious Apache modules redirect traffic to phishing pages disguised as app stores. • The operation uses a sophisticated Linux toolkit with multiple obfuscated tools.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.