Cyber News / Article / Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known asGambling Goblinhas been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.
Check Point Research said it has tracked the campaign since mid-2025.
The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site's own security headers are stripped, allowing the injected content to run freely.
Those pages pose as trusted app stores including Google Play, Microsoft Store, and Amazon, and push online gambling and sports betting behind that facade.
Check Point said the likely goal is search engine optimization (SEO) manipulation at scale, with compromised high-reputation domains, many of them Brazilian government sites, chained together to inflate search rankings.
ANY.RUN reported in July thatat least 20 .gov.br portalsbelonging to Brazilian municipalities and police forces had been used to distribute malware in a campaign it tracks asPhantomEnigma.
"These government systems are part of the delivery chain, not confirmed campaign targets," ANY.RUN said in a report published July 16.
Compromised .gov.br and .jus.br hosts should be handled separately from attacker-controlled infrastructure, ANY.RUN said, because blocking them broadly would disrupt access to government resources.
Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023, and authorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry.
Check Point did not say whether the betting sites promoted through the compromised servers hold that authorization.
Once on a host,Check Point saidthe group deploys the following tools -
The public version of 3snake attaches ptrace to newly spawned sshd and sudo processes and extracts strings related to password-based authentication. Its documentation states that the tool targets rooted servers.
The Hacker News reviewedthe 3snake source on GitHubon September 2, 2026, and confirmed both. The credentials used to administer a compromised server are therefore read by a component the operators control.
Check Point said it hasn't directly observed how the group obtains initial access. An exposed open directory on one of the actor's servers held an ELF binary written in Go that bundles reconnaissance and scanning plugins.
The material published so far includes no count of compromised servers and no module filenames, paths, or hashes that would let administrators check the modules loaded into their own Apache instances.
Parallel phishing networks localized in Vietnamese, Spanish, and English were also identified, along with infrastructure that generates new domains daily. Because the pages already mimic app-download destinations, Check Point said the operators sit "one step from pushing malware straight to victims."
The published summary names no affected organization and does not say whether the compromised servers have been cleaned.
Check Point tied the cluster to Earth Berberoka, an actor Trend Micro documented in 2022 as targeting gambling websites across Asia using malware families historically attributed to Chinese-speaking individuals.
Xnote, a Linux backdoortied to the group, was reported in March during attacks on critical infrastructure in Asia.
oRAT, one of the Linux tools in that arsenal, was documented by Trend Microin April 2022as Earth Berberoka malware, in Windows and macOS samples both flagged as version 0.5.1. The Hacker News confirmed that provenance against Trend Micro's research on September 2, 2026.
ESET documentedat least 65 Windows servers, mainly in Brazil, Thailand, and Vietnam, compromised in June 2025 by GhostRedirector, an actor it assessed with medium confidence as China-aligned, which installed a native Internet Information Services (IIS) module called Gamshen.
"GhostRedirector has developed a malicious native IIS module, Gamshen, that can perform SEO fraud; we believe its purpose is to artificially promote various gambling websites," ESET said.
Gamshen altered the server's responseonly when the request came from Googlebot, leaving ordinary visitors with the page they asked for.
Palo Alto Networks Unit 42 documentedthe same reverse-proxy techniqueon IIS serversin September 2025.
Hunt.io said in July 2025 that it had foundmore than 630,000 URLsgenerated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages to Googlebot while redirecting real users to betting sites.
The company redacted certain indicators in coordination with Brazil's government incident response team, CTIR, while that investigation continued.
"The goal was not to break into systems. It was to control visibility," Hunt.io said.
Related articles
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
3 days ago
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
5 days ago
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
5 days ago

