Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Group Exploits Brazilian Sites for Betting Promotions

Cyber Group Exploits Brazilian Sites for Betting Promotions

Posted on September 2, 2026 By CWS

A cybercrime group known as Gambling Goblin, identified as Chinese-speaking, has been infiltrating web servers operated by Brazilian governmental and educational entities. These malicious actions reroute site traffic to pages under the attackers’ control, which are used to promote online gambling and sports betting.

Malicious Techniques and Objectives

The cybersecurity firm Check Point Research has been monitoring this campaign since mid-2025. The attackers employ malicious Apache modules to act as reverse proxies, leading visitors to phishing sites while maintaining the appearance of legitimate domain traffic. This approach strips sites of their security headers, allowing harmful content to execute seamlessly.

These phishing pages impersonate well-known app stores like Google Play and Microsoft Store, disguising their true intent to push gambling content. The strategy aims to manipulate search engine optimization (SEO), leveraging high-reputation domains, particularly Brazilian government sites, to artificially boost search rankings.

Reported Incidents and Implications

In July, the cybersecurity platform ANY.RUN reported that at least 20 government portals with .gov.br domains were exploited to disseminate malware, a campaign it labels as PhantomEnigma. ANY.RUN emphasized that these systems were part of the distribution network, not necessarily the primary targets.

Blocking these compromised domains indiscriminately could disrupt essential government services, as noted by ANY.RUN. This predicament underscores the delicate balance required in cybersecurity responses.

Tools and Broader Implications

Once servers are compromised, the cybercriminals deploy various tools, including DownPro, a custom downloader, and AlphaAgent, a modular backdoor. Other tools such as oRAT, a remote access trojan, and a 3snake-based credential stealer are used to maintain control and extract sensitive data.

Check Point Research has yet to determine the initial access methods. However, they discovered an exposed directory containing an ELF binary in Go, bundling reconnaissance and scanning tools. The lack of detailed information on compromised servers or module specifics poses challenges for administrators seeking to secure their systems.

Parallel phishing operations in languages like Vietnamese and Spanish have also been identified, indicating a wide-reaching threat. These networks are capable of generating new domains daily, positioning them just a step away from delivering malware directly to unsuspecting users.

Connections to Broader Cyber Threats

Check Point has linked these activities to Earth Berberoka, a group documented by Trend Micro in 2022 for targeting gambling sites across Asia. This group is associated with various malware families historically linked to Chinese-speaking actors.

Furthermore, ESET reported similar incidents involving GhostRedirector, believed to be China-aligned, which compromised servers in Brazil, Thailand, and Vietnam. GhostRedirector uses a native IIS module called Gamshen to perform SEO fraud by altering server responses specifically for Googlebot, while regular visitors see the intended content.

In July 2025, Hunt.io discovered over 630,000 URLs generated on hijacked govt.br subdomains, which presented keyword-stuffed pages to Googlebot while redirecting human users to betting platforms. The company coordinated this discovery with Brazil’s government incident response team, CTIR, as the investigation continued.

The primary aim of these cyber activities appears to be controlling visibility rather than direct system breaches, according to Hunt.io. This complex threat landscape highlights the ongoing challenges in securing digital infrastructures against sophisticated cyber threats.

The Hacker News Tags:ANY.RUN, Apache modules, Betting, Brazil, Check Point Research, Cybercrime, Cybersecurity, Earth Berberoka, GhostRedirector, government sites, Hacking, Malware, online gambling, Phishing, SEO manipulation

Post navigation

Previous Post: Russian Indicted for Massive Freelance Malware Attack
Next Post: OpenAI’s Astra Achieves Milestone in Cybersecurity

Related Posts

F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution The Hacker News
Cybersecurity Threats: DeFi Hack & AI Vulnerabilities Cybersecurity Threats: DeFi Hack & AI Vulnerabilities The Hacker News
Wazuh for Regulatory Compliance Wazuh for Regulatory Compliance The Hacker News
NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors NightEagle APT Exploits Microsoft Exchange Flaw to Target China’s Military and Tech Sectors The Hacker News
Critical Flaw in MCP Protocol Poses Major AI Supply Chain Risk Critical Flaw in MCP Protocol Poses Major AI Supply Chain Risk The Hacker News
Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TukTuk Malware Exploited by Ransomware Hackers
  • OpenAI’s Astra Achieves Milestone in Cybersecurity
  • Cyber Group Exploits Brazilian Sites for Betting Promotions
  • Russian Indicted for Massive Freelance Malware Attack
  • Anthropic Enhances Security With Enterprise Safeguards

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TukTuk Malware Exploited by Ransomware Hackers
  • OpenAI’s Astra Achieves Milestone in Cybersecurity
  • Cyber Group Exploits Brazilian Sites for Betting Promotions
  • Russian Indicted for Massive Freelance Malware Attack
  • Anthropic Enhances Security With Enterprise Safeguards

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark