Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
AI Summary
A Chinese-speaking cybercrime group dubbed Gambling Goblin has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules to redirect traffic to online gambling and sports betting pages. The attack infrastructure uses compromised high-reputation .gov.br and .jus.br domains to manipulate search engine rankings through SEO fraud. The group deploys tools including DownPro, AlphaAgent, oRAT, a 3snake-based credential stealer, and an SSH brute-forcer. Check Point links the group to Earth Berberoka, previously documented by Trend Micro, and notes the use of reverse-proxy techniques to serve malicious content while preserving the appearance of legitimate traffic.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | 3snake | Details → |