Chinese-Language Hackers Hijack Government Servers to Power Gambling Phishing Network
Security researchers have identified a Chinese-language cybercriminal group compromising Brazilian government and education servers. The attackers are using these trusted, legitimate sites to build a reverse-proxy network that hosts gambling-themed phishing pages.
By routing traffic through compromised government and education infrastructure, the attackers can hide the true location of their phishing sites and lend an air of legitimacy to malicious traffic, making detection harder for security teams and internet users alike. While this campaign is currently focused on government and education targets, the technique of abusing trusted domains for phishing infrastructure is broadly applicable and could affect organisations of any size whose web servers are poorly secured or monitored.