Breaking
Cyber CrimeDeveloping Story

Brazilian sites hijacked in SEO fraud ruse

Chinese-speaking Gambling Goblin group turns Brazilian government sites into SEO and phishing infrastructure.

··2 hours ago·4 min read
a close up of a server in a server room
Photo by Tyler on Unsplash

Brazilian government websites, long a battleground for home-grown banking trojans, appear to have been quietly repurposed by a foreign cybercrime operation. The campaign, which researchers have been tracking since mid-2025, turned compromised federal, state, and municipal domains into proxies for phishing pages that peddle online gambling—an SEO fraud scheme that may have gone unnoticed for months.

New actor in Brazil's threat landscape

Researchers at Check Point Research (CPR) reported on September 2 that a Chinese-speaking threat cluster they've named 'Gambling Goblin' has been running the operation. CPR assessed with 'medium-to-high confidence' that the group is linked to Earth Berberoka, a Chinese-speaking cluster documented by Trend Micro in 2022 as focusing on gambling platforms serving Chinese-speaking users.

The connection is based on overlapping tooling, operator artifacts, and infrastructure—including the use of the oRAT remote access trojan, Chinese-language strings, and domains that mimic trusted technology brands. CPR described the campaign as marking a shift from Brazil's traditional banking trojans to a foreign operator, attracted by one of the world's fastest-growing online betting markets.

Backdoor via Apache modules

The attackers installed custom Apache modules on compromised web servers that functioned as reverse proxies, quietly routing a subset of visitors from the trusted Brazilian sites to attacker-controlled phishing pages. According to CPR, these modules targeted specific URL paths and were capable of stripping existing Content-Security-Policy headers, replacing them with permissive settings that allowed external and dynamically generated scripts to execute.

An installer compiled each module on the victim server, then deleted the source code and 'timestomped' the resulting binary to make it blend in with legitimate Apache modules—a tactic designed to evade file-integrity checks and forensic analysis.

Phishing pages mimic app stores

The phishing pages impersonated well-known destinations including Google Play, the Microsoft Store, and Amazon. They were localized for Brazilian users and promoted online gambling and sports betting. The overall goal appears to be SEO fraud: by hosting this content on high-authority government domains, the attackers aimed to boost the pages' search engine rankings and drive traffic to their gambling sites.

Victims span all government levels

The compromised organizations spanned federal, state, and municipal government, including a ministry, a national public agency, a state legislative assembly, courts of accounts, and a state-owned utility. Municipal administrations made up the largest share of victims. The campaign also affected commercial Brazilian sites, such as local news organizations, healthcare providers, and business associations.

The breadth of the victim list suggests the attackers cast a wide net across Brazil's internet infrastructure, rather than targeting specific agencies. CPR noted that the compromised entities' high domain authority made them valuable for manipulating search results.

Linux toolkit behind the scenes

The web-server activity was part of a larger Linux malware toolkit. CPR identified the DownPro downloader, backdoors including AlphaAgent and oRAT, the 3snake-based PasswordHarvester credential stealer, and an SSH brute-forcer. Most of these tools were wrapped in packing and virtualization layers to slow down analysis.

The researchers also found a reconnaissance agent that used tools such as httpx, naabu, Nuclei, and subfinder to map internet-facing infrastructure and identify services running on potential targets.

AlphaAgent supported remote command execution (RCE), file transfers, tunneling, and host discovery, while oRAT provided remote administration capabilities. CPR noted an 'AI plugin execution path' in a newer AlphaAgent build, although the sample did not reveal what the plugin did.

Beyond Brazil

The infrastructure was not confined to Brazil. CPR found phishing pages localized in Vietnamese, Spanish, and English, alongside systems that generated fresh domains daily. This suggests the operation could expand its reach beyond the Brazilian market.

The researchers warned that the setup created a potential path to direct malware distribution because the phishing infrastructure already imitated legitimate app stores—meaning a visitor could potentially be tricked into downloading malicious files disguised as legitimate applications.

Mitigation and detection advice

CPR advised organizations to audit their Apache and SSH configurations and to hunt for rogue modules and masqueraded processes. The use of timestomped files and custom Apache modules makes detection difficult, but regular integrity checks on web server binaries and monitoring for unusual outbound traffic could help uncover compromises.

The researchers warned the setup created a potential path to direct malware distribution because the phishing infrastructure already imitated legitimate app stores.

— Check Point Research, as reported in the source article

Why it matters

This campaign underscores a worrying evolution in SEO fraud: attackers are no longer just defacing websites or stuffing keywords into spam pages. By hijacking trusted government domains and deploying sophisticated Apache modules, they're turning the web's trust infrastructure against itself. For Brazilian organizations, the risk extends beyond reputational damage—compromised servers can be used to host malware or launder further attacks. The connection to an established Chinese-speaking cluster suggests this is not an isolated incident but part of a broader playbook that could be applied in other countries with growing online gambling markets.

#seo fraud#brazil#gambling goblin#phishing#linux malware#apache

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories