Gambling Goblin Hijacks Brazilian Government Servers for SEO Manipulation and Betting Scams
A Chinese-speaking cybercrime group, dubbed **Gambling Goblin**, has been observed compromising web servers belonging to Brazilian government and educational institutions. The attackers are deploying malicious Apache modules to redirect visitors to fake app stores promoting online gambling and sports betting, primarily for large-scale search engine optimization (SEO) manipulation.
A Chinese-speaking cybercrime cluster known as **Gambling Goblin** has been installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions. The group uses these modules to divert visitors to attacker-controlled pages promoting online gambling and sports betting.
**Check Point Research** has been tracking this campaign since mid-2025.

The malicious modules function as reverse-proxies, directing visitors to a series of phishing pages while making the traffic appear to originate from the legitimate domain. Crucially, the site's own security headers are stripped, allowing the injected content to execute without hindrance.
These deceptive pages masquerade as trusted app stores, including **Google Play**, **Microsoft Store**, and **Amazon**, to push online gambling and sports betting content.
**Check Point** suggests the primary objective is large-scale SEO manipulation. By compromising high-reputation domains, many of which are Brazilian government sites, the attackers aim to artificially inflate search rankings for their betting platforms.
In July, **ANY.RUN** reported that at least 20 `.gov.br` portals belonging to Brazilian municipalities and police forces had been used to distribute malware in a campaign it tracks as **PhantomEnigma**.
"These government systems are part of the delivery chain, not confirmed campaign targets," **ANY.RUN** stated in a report published July 16.
**ANY.RUN** further advised that compromised `.gov.br` and `.jus.br` hosts should be handled distinctly from attacker-controlled infrastructure. Broadly blocking these domains could disrupt access to essential government resources.
Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023, authorizing operators to use `.bet.br` domains issued through **Registro.br**, Brazil's domain registry. **Check Point** did not confirm whether the betting sites promoted through the compromised servers hold such authorization.

### Attacker Toolset
Once a host is compromised, **Check Point** details the deployment of several tools:
* **DownPro**: A custom downloader.
* **AlphaAgent**: A modular backdoor.
* **oRAT**: A remote access trojan.
* A **3snake-based credential stealer**.
* An SSH brute-forcer.
* A plugin-driven reconnaissance agent.
The public version of **3snake** attaches `ptrace` to newly spawned `sshd` and `sudo` processes to extract strings related to password-based authentication. Its documentation indicates the tool targets rooted servers. The credentials used to administer a compromised server are thus accessible to the operators.
**Check Point** has not directly observed the initial access vector. However, an exposed open directory on one of the actor's servers contained an **ELF** binary written in **Go** that bundles reconnaissance and scanning plugins.
### Broader Campaign Context
Parallel phishing networks localized in Vietnamese, Spanish, and English have also been identified, alongside infrastructure that generates new domains daily. Given that the pages already mimic app-download destinations, **Check Point** warns that the operators are "one step from pushing malware straight to victims."
**Check Point** has linked this cluster to **Earth Berberoka**, an actor **Trend Micro** documented in 2022. **Earth Berberoka** is known for targeting gambling websites across Asia using malware families historically attributed to Chinese-speaking individuals. **Xnote**, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia.
**oRAT**, one of the Linux tools in this arsenal, was documented by **Trend Micro** in April 2022 as **Earth Berberoka** malware, with Windows and macOS samples both flagged as version 0.5.1.
**ESET** documented at least 65 Windows servers, primarily in Brazil, Thailand, and Vietnam, compromised in June 2025 by **GhostRedirector**. This actor, assessed with medium confidence as China-aligned, installed a native **Internet Information Services (IIS)** module called **Gamshen**.
"**GhostRedirector** has developed a malicious native IIS module, **Gamshen**, that can perform SEO fraud; we believe its purpose is to artificially promote various gambling websites," **ESET** stated. **Gamshen** specifically altered the server's response only when the request originated from **Googlebot**, leaving ordinary visitors with the expected page.
**Palo Alto Networks Unit 42** documented the same reverse-proxy technique on IIS servers in September 2025.
**Hunt.io** reported in July 2025 finding more than 630,000 URLs generated on hijacked `.gov.br` subdomains. These served keyword-stuffed government-style pages to **Googlebot** while redirecting real users to betting sites. The company redacted certain indicators in coordination with Brazil's government incident response team, **CTIR**, during their ongoing investigation.
"The goal was not to break into systems. It was to control visibility," **Hunt.io** commented, highlighting the SEO-centric nature of these attacks.