logo

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

ID: 832f9f35-32cf-5202-bfa0-7847498cdb36

STIX ID: report--832f9f35-32cf-5202-bfa0-7847498cdb36

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-09-02

Date Updated: 2026-09-11

...
...

Check Point Research attributes a sustained SEO-fraud campaign since mid-2025 to a Chinese-speaking cybercrime cluster (Gambling Goblin/Earth Berberoka) that installed custom Apache modules on compromised Brazilian government, municipal and commercial websites to proxy selected visitors to localized phishing pages impersonating app stores and promoting gambling. The operation is backed by a large Linux malware toolkit (DownPro downloader, AlphaAgent, oRAT, PasswordHarvester, SSH brute-forcers) and reconnaissance tooling, creating credential-theft and potential malware distribution pathways; CPR recommends auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.