A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.
Check Point Research said it has tracked the campaign since mid-2025.
The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site's own security headers are stripped, allowing the injected content to run freely.
Those pages pose as trusted app stores including Google Play, Microsoft Store, and Amazon, and push online gambling and sports betting behind that facade.
Check Point said the likely goal is search engine optimization (SEO) manipulation at scale, with compromised high-reputation domains, many of them Brazilian government sites, chained together to inflate search rankings.
ANY.RUN reported in July that at least 20 .gov.br portals belonging to Brazilian municipalities and police forces had been used to distribute malware in a campaign it tracks as PhantomEnigma.
"These government systems are part of the delivery chain, not confirmed campaign targets," ANY.RUN said in a report published July 16.
Compromised .gov.br and .jus.br hosts should be handled separately from attacker-controlled infrastructure, ANY.RUN said, because blocking them broadly would disrupt access to government resources.
Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023, and authorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry.
Check Point did not say whether the betting sites promoted through the compromised servers hold that authorization.
Once on a host, Check Point said the group deploys the following tools -
- DownPro, a custom downloader
- AlphaAgent, a modular backdoor
- oRAT, a remote access trojan (RAT)
- A 3snake-based credential stealer
- An SSH brute-forcer
- A plugin-driven reconnaissance agent
The public version of 3snake attaches ptrace to newly spawned sshd and sudo processes and extracts strings related to password-based authentication. Its documentation states that the tool targets rooted servers.
The Hacker News reviewed the 3snake source on GitHub on September 2, 2026, and confirmed both. The credentials used to administer a compromised server are therefore read by a component the operators control.
Check Point said it hasn't directly observed how the group obtains initial access. An exposed open directory on one of the actor's servers held an ELF binary written in Go that bundles reconnaissance and scanning plugins.
The material published so far includes no count of compromised servers and no module filenames, paths, or hashes that would let administrators check the modules loaded into their own Apache instances.
Parallel phishing networks localized in Vietnamese, Spanish, and English were also identified, along with infrastructure that generates new domains daily. Because the pages already mimic app-download destinations, Check Point said the operators sit "one step from pushing malware straight to victims."
The published summary names no affected organization and does not say whether the compromised servers have been cleaned.
Check Point tied the cluster to Earth Berberoka, an actor Trend Micro documented in 2022 as targeting gambling websites across Asia using malware families historically attributed to Chinese-speaking individuals.
Xnote, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia.
oRAT, one of the Linux tools in that arsenal, was documented by Trend Micro in April 2022 as Earth Berberoka malware, in Windows and macOS samples both flagged as version 0.5.1. The Hacker News confirmed that provenance against Trend Micro's research on September 2, 2026.
ESET documented at least 65 Windows servers , mainly in Brazil, Thailand, and Vietnam, compromised in June 2025 by GhostRedirector, an actor it assessed with medium confidence as China-aligned, which installed a native Internet Information Services (IIS) module called Gamshen.
"GhostRedirector has developed a malicious native IIS module, Gamshen, that can perform SEO fraud; we believe its purpose is to artificially promote various gambling websites," ESET said.
Gamshen altered the server's response only when the request came from Googlebot, leaving ordinary visitors with the page they asked for.
Palo Alto Networks Unit 42 documented the same reverse-proxy technique on IIS servers in September 2025.
Hunt.io said in July 2025 that it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages to Googlebot while redirecting real users to betting sites.
The company redacted certain indicators in coordination with Brazil's government incident response team, CTIR, while that investigation continued.
"The goal was not to break into systems. It was to control visibility," Hunt.io said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

2 hours ago
2













