Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
ID: 0cb84f7f-8e95-5dbc-aaac-9a872ce2f348
STIX ID: report--0cb84f7f-8e95-5dbc-aaac-9a872ce2f348
Feed Name: Check Point Research
Check Point Research documents a sustained mid-2025 campaign by a Chinese-speaking cluster called "Gambling Goblin" tied to Earth Berberoka that compromises high-reputation web servers—many Brazilian government sites—by installing malicious Apache modules which silently reverse-proxy visitors to attacker-controlled phishing pages and strip security headers; the operators run large-scale SEO manipulation to push gambling and fake app-store pages and deploy a sophisticated Linux toolkit (DownPro, AlphaAgent, oRAT, PasswordHarvester) enabling reconnaissance, credential theft, remote access, tunneling, and lateral movement, with infrastructure and domain-generation capabilities spanning multiple languages and regions and a long list of IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
