Threat Intelligence

Chinese-Language Hackers Hijack Government Servers to Power Gambling Phishing Network

Dark Reading · 8 Sept 2026
Key Takeaway Regularly audit your website and server infrastructure for unauthorised changes, and ensure hosting accounts use strong authentication so attackers cannot quietly turn your site into a launchpad for scams.

Security researchers have identified a Chinese-language cybercriminal group compromising Brazilian government and education servers. The attackers are using these trusted, legitimate sites to build a reverse-proxy network that hosts gambling-themed phishing pages.

By routing traffic through compromised government and education infrastructure, the attackers can hide the true location of their phishing sites and lend an air of legitimacy to malicious traffic, making detection harder for security teams and internet users alike. While this campaign is currently focused on government and education targets, the technique of abusing trusted domains for phishing infrastructure is broadly applicable and could affect organisations of any size whose web servers are poorly secured or monitored.

phishing server compromise reverse proxy government security SMB awareness

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.