Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
ID: 832f9f35-32cf-5202-bfa0-7847498cdb36
STIX ID: report--832f9f35-32cf-5202-bfa0-7847498cdb36
Feed Name: Infosecurity Magazine (News)
Check Point Research attributes a sustained SEO-fraud campaign since mid-2025 to a Chinese-speaking cybercrime cluster (Gambling Goblin/Earth Berberoka) that installed custom Apache modules on compromised Brazilian government, municipal and commercial websites to proxy selected visitors to localized phishing pages impersonating app stores and promoting gambling. The operation is backed by a large Linux malware toolkit (DownPro downloader, AlphaAgent, oRAT, PasswordHarvester, SSH brute-forcers) and reconnaissance tooling, creating credential-theft and potential malware distribution pathways; CPR recommends auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
