VYPR
researchPublished Sep 2, 2026· 1 source

Chinese Actor 'Gambling Goblin' Hijacks Brazilian Government Sites for SEO Fraud and Phishing

A Chinese-speaking cybercrime group, dubbed Gambling Goblin, is compromising Brazilian government and educational servers to host phishing pages that mimic app stores, pushing online gambling content and manipulating search engine results.

Check Point Research has uncovered a sustained cyber-espionage and fraud campaign targeting Brazilian organizations, primarily government and educational institutions, since mid-2025. The threat actor, identified as a Chinese-speaking group and named "Gambling Goblin," shows connections to a previously documented entity known as Earth Berberoka, which historically focused on gambling-related sites in Asia. This operation represents a significant shift, moving Brazil's typical threat landscape from local banking trojans to foreign actors actively compromising infrastructure.

The core of Gambling Goblin's operation involves repurposing compromised web servers into stealthy proxies. Attackers compile and install malicious Apache modules on these victim servers. These modules silently redirect visitors to attacker-controlled phishing pages, while the traffic still appears to originate from the legitimate, compromised domain. To facilitate this, the site's own security headers are stripped, allowing injected content to run without interference.

The phishing pages are designed to impersonate popular and trusted app stores, including Google Play, Microsoft Store, and Amazon. However, their true purpose is to lure unsuspecting users into online gambling and sports betting platforms. The group achieves large-scale reach by chaining together compromised high-reputation domains, many of which belong to Brazilian government entities. This tactic leverages the established trust and search engine ranking of these legitimate sites to inflate their own content's visibility and hijack organic traffic.

Once a server is compromised, Gambling Goblin deploys a comprehensive and heavily obfuscated Linux toolkit. This arsenal includes a custom downloader named "DownPro," multiple backdoors such as the modular "AlphaAgent" and the "oRAT" remote access trojan, a "3snake"-based credential stealer, an SSH brute-forcer, and a plugin-driven reconnaissance agent. A key characteristic of these tools is their extensive use of packing and virtualization layers, designed to significantly slow down analysis efforts and evade detection by security software.

Evidence suggests this operation is not confined to Brazil. Researchers have identified parallel phishing networks localized for Vietnamese, Spanish, and English-speaking audiences. Furthermore, the group utilizes infrastructure that generates new domains daily, indicating a model built for scalability and potential expansion into new geographical regions. This broad reach underscores the actor's ambition beyond a single target market.

The current scheme of SEO manipulation and phishing for gambling traffic carries a latent risk of escalation. Because the compromised infrastructure already mimics legitimate app-download destinations, it is a simple configuration change away from distributing malware directly to victims. This presents a significant potential threat beyond the current search-fraud and gambling-luring activities.

While the group's initial access methods remain unobserved, analysis of a compromised server revealed an exposed open directory containing an ELF binary written in Go. This "cam-agent" tool appears to be a sophisticated attack-surface-mapping pipeline for internet-facing targets, bundling numerous reconnaissance and scanning plugins. It communicates with its command-and-control server over gRPC, using embedded certificates for authentication, and leverages well-known open-source penetration testing tools like "dirprobe," "httpx," "naabu," "nuclei," "subfinder," and "whatweb" as modules.

Synthesized by Vypr AI