A cybercrime group known as Gambling Goblin, identified as Chinese-speaking, has been infiltrating web servers operated by Brazilian governmental and educational entities. These malicious actions reroute site traffic to pages under the attackers’ control, which are used to promote online gambling and sports betting.
Malicious Techniques and Objectives
The cybersecurity firm Check Point Research has been monitoring this campaign since mid-2025. The attackers employ malicious Apache modules to act as reverse proxies, leading visitors to phishing sites while maintaining the appearance of legitimate domain traffic. This approach strips sites of their security headers, allowing harmful content to execute seamlessly.
These phishing pages impersonate well-known app stores like Google Play and Microsoft Store, disguising their true intent to push gambling content. The strategy aims to manipulate search engine optimization (SEO), leveraging high-reputation domains, particularly Brazilian government sites, to artificially boost search rankings.
Reported Incidents and Implications
In July, the cybersecurity platform ANY.RUN reported that at least 20 government portals with .gov.br domains were exploited to disseminate malware, a campaign it labels as PhantomEnigma. ANY.RUN emphasized that these systems were part of the distribution network, not necessarily the primary targets.
Blocking these compromised domains indiscriminately could disrupt essential government services, as noted by ANY.RUN. This predicament underscores the delicate balance required in cybersecurity responses.
Tools and Broader Implications
Once servers are compromised, the cybercriminals deploy various tools, including DownPro, a custom downloader, and AlphaAgent, a modular backdoor. Other tools such as oRAT, a remote access trojan, and a 3snake-based credential stealer are used to maintain control and extract sensitive data.
Check Point Research has yet to determine the initial access methods. However, they discovered an exposed directory containing an ELF binary in Go, bundling reconnaissance and scanning tools. The lack of detailed information on compromised servers or module specifics poses challenges for administrators seeking to secure their systems.
Parallel phishing operations in languages like Vietnamese and Spanish have also been identified, indicating a wide-reaching threat. These networks are capable of generating new domains daily, positioning them just a step away from delivering malware directly to unsuspecting users.
Connections to Broader Cyber Threats
Check Point has linked these activities to Earth Berberoka, a group documented by Trend Micro in 2022 for targeting gambling sites across Asia. This group is associated with various malware families historically linked to Chinese-speaking actors.
Furthermore, ESET reported similar incidents involving GhostRedirector, believed to be China-aligned, which compromised servers in Brazil, Thailand, and Vietnam. GhostRedirector uses a native IIS module called Gamshen to perform SEO fraud by altering server responses specifically for Googlebot, while regular visitors see the intended content.
In July 2025, Hunt.io discovered over 630,000 URLs generated on hijacked govt.br subdomains, which presented keyword-stuffed pages to Googlebot while redirecting human users to betting platforms. The company coordinated this discovery with Brazil’s government incident response team, CTIR, as the investigation continued.
The primary aim of these cyber activities appears to be controlling visibility rather than direct system breaches, according to Hunt.io. This complex threat landscape highlights the ongoing challenges in securing digital infrastructures against sophisticated cyber threats.
