A Chinese-speaking cybercrime group has been planting malicious Apache modules on compromised web servers operated by Brazilian government and educational institutions, then using those servers to redirect visitors toward attacker-controlled pages that promote online gambling and sports betting, according to a report Check Point Research published this week. The security firm said it's been monitoring the campaign, which it calls Gambling Goblin, since the middle of 2025. The modules work by reverse-proxying visitors to a collection of phishing pages while traffic continues to look like it's coming from the legitimate domain, with the site's own security headers removed so the injected content can execute without restriction.
The attackers deploy those phishing pages to mimic trusted app stores such as Google Play, Microsoft Store, and Amazon, then use that facade to push online gambling and sports betting offers. Check Point assessed that the operation's likely objective is large-scale search engine optimization manipulation, leveraging compromised high-reputation domains—many of them Brazilian government sites—to artificially boost search rankings. The research firm ANY.RUN reported in July that at least 20 .gov.br portals belonging to Brazilian municipalities and police forces had been exploited to distribute malware in a campaign it tracks as PhantomEnigma. Hunt.io said in July 2025 that it had discovered more than 630,000 URLs created on hijacked gov.br subdomains, delivering keyword-stuffed government-style pages to Googlebot while sending actual users to betting sites.
Once inside a compromised host, the group installs a suite of tools including DownPro, a custom downloader; AlphaAgent, a modular backdoor; oRAT, a remote access trojan; a credential stealer based on 3snake; an SSH brute-forcer; and a plugin-driven reconnaissance agent, the report states. The public version of 3snake attaches ptrace to newly spawned sshd and sudo processes and pulls out strings tied to password-based authentication, with its documentation indicating the tool targets rooted servers. Check Point said it hasn't directly witnessed how the group secures initial access, though an exposed open directory on one of the actor's servers contained an ELF binary written in Go that bundles reconnaissance and scanning plugins. Because the phishing pages already mimic app-download destinations, Check Point said the operators are positioned "one step from pushing malware straight to victims."
The campaign exploits a structural vulnerability in how search engines assess legitimacy: government domains carry inherent trust, and chaining them together can inflate rankings for any content the attacker chooses to surface. Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023, and authorized operators to run on .bet.br domains issued through Registro.br, the country's domain registry, though Check Point did not confirm whether the betting sites promoted through the compromised servers hold that authorization. Check Point linked the cluster to Earth Berberoka, an actor Trend Micro documented in 2022 as targeting gambling websites across Asia using malware families historically attributed to Chinese-speaking individuals. ESET documented at least 65 Windows servers, mainly in Brazil, Thailand, and Vietnam, compromised in June 2025 by GhostRedirector, an actor it assessed with medium confidence as China-aligned, which installed a native Internet Information Services module called Gamshen that performed SEO fraud by altering server responses only when requests came from Googlebot. The published summary names no affected organization and does not say whether the compromised servers have been cleaned. Defenders face a tactical dilemma: blocking compromised government infrastructure would cut off access to public services, yet leaving it online extends the attacker's reach and credibility in the eyes of both search algorithms and end users.

