Fast Facts
- A Chinese-speaking cybercrime group, Gambling Goblin, compromises Brazilian government and educational servers to host fake app store pages promoting gambling, using reverse-proxy techniques to manipulate search rankings and divert traffic.
- The group deploys malware tools like DownPro, AlphaAgent, oRAT, and credential stealers on compromised servers, enabling remote control, data theft, and persistent access.
- Attackers manipulate SEO by injecting malicious modules (e.g., Gamshen) into IIS servers, artificially boosting gambling website visibility while disguising malicious redirects for real users, leading to widespread misinformation and financial fraud.
Threat, Attack Techniques, and Targets
A group called Gambling Goblin, which speaks Chinese, carries out this attack. They install malicious Apache modules on servers used by the Brazilian government and schools. Their main goal is to redirect visitors to fake pages that promote online gambling and sports betting. The campaign has been active since mid-2025 according to Check Point Research.
The attackers use reverse-proxy techniques to make traffic from visitors look normal. Their malicious modules strip security headers from the website, allowing injected content to run freely. The fake pages pretend to be trusted app stores like Google Play, Microsoft Store, and Amazon. These pages push gambling and betting content.
The group also targets high-reputation domains, including many Brazilian government sites. They use different tools once on a server. These tools include custom downloaders, backdoors, remote access Trojans, credential stealer, SSH brute-force tools, and reconnaissance agents.
It is not clear how they initially gain access to the servers. However, they have used open directories filled with malicious binaries. Also, they have created phishing networks in Vietnamese, Spanish, and English. The infrastructure generates new fake domains daily, enabling ongoing attacks.
The campaign appears linked to Earth Berberoka, a group known for targeting gambling websites in Asia. They have used malware like Xnote and oRAT, which are also tied to this group. Overall, the threat focuses on hijacking servers, stealing credentials, and redirecting visitors.
Impact, Security Implications, and Remediation Guidance
This attack can cause serious consequences. It can allow the attackers to control the visibility of government and other sites. Visitors may be shown fake pages, risking scams or malware. Also, search engines may rank these fake pages higher, spreading the malicious content further.
The compromised sites may assist in spreading malware or fake apps. The attackers can steal sensitive information, such as login credentials. This can lead to wider security issues, including data theft and loss of trust in affected institutions.
Because the attack uses sophisticated techniques and multiple tools, it presents significant security challenges. The attackers leverage legitimate server functions to hide their activities. This makes detection and removal difficult.
If your organization detects similar issues, it is recommended to consult with your security vendor or relevant authority. They can provide specific guidance, including cleaning compromised servers and preventing future attacks. Blocking the attackers’ infrastructure broadly could disrupt legitimate government services. Therefore, careful, targeted remediation is advised.
Discover More Technology Insights
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
