Gambling Goblin repurposes Brazil government sites for SEO
A Chinese-speaking cybercrime group has compromised government and education websites across Brazil and turned trusted domains into infrastructure for a search-engine optimisation fraud operation, security researchers disclosed on Wednesday. Check Point Research said the campaign, active since mid-2025, uses malicious Apache modules installed on breached web servers to redirect visitors and…
A Chinese-speaking cybercrime group, dubbed Gambling Goblin, has exploited compromised Brazilian government and educational websites to create a search engine optimization (SEO) fraud operation, according to security researchers. The campaign, which has been active since mid-2025, involves installing malicious Apache modules on breached web servers.
These modules act as reverse proxies, redirecting visitors and search crawlers towards attacker-controlled gambling and sports betting pages while preserving the legitimate website address in the browser. Researchers have identified the group as Earth Berberoka, a threat group previously known for targeting online gambling platforms in Asia.
Gambling Goblin has leveraged oRAT, a Go-based remote-access trojan, and other tools associated with Earth Berberoka, while also employing Chinese-language strings and custom tools. The group exploits the reputation of compromised websites, rather than merely changing their visible content. By using custom Apache modules as reverse proxies, the attackers can retrieve fraudulent pages from remote servers while maintaining the appearance of originating from government domains.
These modules also disable Content-Security-Policy headers, allowing injected or externally hosted scripts to run with diminished restrictions. The fraudulent pages mimic app platforms such as Google Play, Microsoft Store, and Amazon, using fabricated reviews, ratings, and metadata to promote online gambling and sports betting to Brazilian users.
The compromised sites include government bodies at federal, state, and municipal levels, as well as some commercial domains. The attackers have not disclosed the names of the affected institutions, but researchers found an exposed directory containing a Go-based reconnaissance tool designed to map internet-facing systems and entry points.
Once access is gained, the group deploys a heavily obfuscated Linux toolkit, including a downloader, backdoors, a credential stealer, an SSH brute-forcing utility, and reconnaissance components. The malware, oRAT, offers remote control of infected Linux hosts, enabling command execution, file transfers, port scanning, proxy functions, and embedded SSH access.
The operation extends beyond Brazil, with phishing infrastructure localized for Vietnamese, Spanish, and English-speaking audiences, and systems generating new domains daily. Some of these domains direct users to Chinese-language gambling and adult-content sites, mirroring the group's earlier operations against gambling websites serving Chinese-speaking audiences.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.