Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Group Exploits Brazilian Sites for Betting Promotions

Cyber Group Exploits Brazilian Sites for Betting Promotions

Posted on September 2, 2026 By CWS

A cybercrime group known as Gambling Goblin, identified as Chinese-speaking, has been infiltrating web servers operated by Brazilian governmental and educational entities. These malicious actions reroute site traffic to pages under the attackers’ control, which are used to promote online gambling and sports betting.

Malicious Techniques and Objectives

The cybersecurity firm Check Point Research has been monitoring this campaign since mid-2025. The attackers employ malicious Apache modules to act as reverse proxies, leading visitors to phishing sites while maintaining the appearance of legitimate domain traffic. This approach strips sites of their security headers, allowing harmful content to execute seamlessly.

These phishing pages impersonate well-known app stores like Google Play and Microsoft Store, disguising their true intent to push gambling content. The strategy aims to manipulate search engine optimization (SEO), leveraging high-reputation domains, particularly Brazilian government sites, to artificially boost search rankings.

Reported Incidents and Implications

In July, the cybersecurity platform ANY.RUN reported that at least 20 government portals with .gov.br domains were exploited to disseminate malware, a campaign it labels as PhantomEnigma. ANY.RUN emphasized that these systems were part of the distribution network, not necessarily the primary targets.

Blocking these compromised domains indiscriminately could disrupt essential government services, as noted by ANY.RUN. This predicament underscores the delicate balance required in cybersecurity responses.

Tools and Broader Implications

Once servers are compromised, the cybercriminals deploy various tools, including DownPro, a custom downloader, and AlphaAgent, a modular backdoor. Other tools such as oRAT, a remote access trojan, and a 3snake-based credential stealer are used to maintain control and extract sensitive data.

Check Point Research has yet to determine the initial access methods. However, they discovered an exposed directory containing an ELF binary in Go, bundling reconnaissance and scanning tools. The lack of detailed information on compromised servers or module specifics poses challenges for administrators seeking to secure their systems.

Parallel phishing operations in languages like Vietnamese and Spanish have also been identified, indicating a wide-reaching threat. These networks are capable of generating new domains daily, positioning them just a step away from delivering malware directly to unsuspecting users.

Connections to Broader Cyber Threats

Check Point has linked these activities to Earth Berberoka, a group documented by Trend Micro in 2022 for targeting gambling sites across Asia. This group is associated with various malware families historically linked to Chinese-speaking actors.

Furthermore, ESET reported similar incidents involving GhostRedirector, believed to be China-aligned, which compromised servers in Brazil, Thailand, and Vietnam. GhostRedirector uses a native IIS module called Gamshen to perform SEO fraud by altering server responses specifically for Googlebot, while regular visitors see the intended content.

In July 2025, Hunt.io discovered over 630,000 URLs generated on hijacked govt.br subdomains, which presented keyword-stuffed pages to Googlebot while redirecting human users to betting platforms. The company coordinated this discovery with Brazil’s government incident response team, CTIR, as the investigation continued.

The primary aim of these cyber activities appears to be controlling visibility rather than direct system breaches, according to Hunt.io. This complex threat landscape highlights the ongoing challenges in securing digital infrastructures against sophisticated cyber threats.

The Hacker News Tags:ANY.RUN, Apache modules, Betting, Brazil, Check Point Research, Cybercrime, Cybersecurity, Earth Berberoka, GhostRedirector, government sites, Hacking, Malware, online gambling, Phishing, SEO manipulation

Post navigation

Previous Post: Russian Indicted for Massive Freelance Malware Attack
Next Post: OpenAI’s Astra Achieves Milestone in Cybersecurity

Related Posts

Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data Researchers Find ChatGPT Vulnerabilities That Let Attackers Trick AI Into Leaking Data The Hacker News
Privacy in the Age of Agentic AI Privacy in the Age of Agentic AI The Hacker News
China’s Massistant Tool Secretly Extracts SMS, GPS Data, and Images From Confiscated Phones China’s Massistant Tool Secretly Extracts SMS, GPS Data, and Images From Confiscated Phones The Hacker News
Critical Flaw in AI Platform Writer Poses Security Risks Critical Flaw in AI Platform Writer Poses Security Risks The Hacker News
New Android Malware Uses AI for Persistent Threats New Android Malware Uses AI for Persistent Threats The Hacker News
Enterprise Security Gaps: Insights from 25 Million Alerts Enterprise Security Gaps: Insights from 25 Million Alerts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark