Security News

Chinese-Speaking Hackers Hijack Brazilian Government Sites for Gambling SEO Scam

Infosecurity Magazine · 3 Sept 2026
Key Takeaway Australian businesses running public-facing web servers should regularly audit installed modules, monitor for unauthorized changes to security headers, and patch server software promptly to avoid becoming unwitting infrastructure for fraud campaigns.

Security researchers at Check Point Research have uncovered a campaign, active since mid-2025, in which a Chinese-speaking cybercrime cluster named Gambling Goblin compromised Brazilian government, education, and commercial websites to power an SEO fraud and phishing operation. The group is believed to be linked to Earth Berberoka, a cluster previously documented targeting gambling platforms for Chinese-speaking users, based on shared tools, infrastructure, and coding artifacts.

The attackers installed custom, disguised software modules on compromised web servers that acted as invisible traffic routers. These modules selectively redirected certain visitors to phishing pages impersonating Google Play, the Microsoft Store, and Amazon, all localized for Brazilian audiences and promoting online gambling and sports betting. To make the redirects work, the malicious modules altered security headers on the compromised sites, allowing attacker-controlled scripts to run, and were disguised to look like legitimate Apache components, complete with altered file timestamps to avoid detection.

Victims included Brazilian federal, state, and municipal government bodies, courts, a state-owned utility, and commercial organizations such as news outlets and healthcare providers, with municipal government sites most heavily affected. Researchers also found the same infrastructure hosting a broader Linux malware toolkit, including downloaders, backdoors, a credential-stealing tool, and a tool for brute-forcing SSH logins, many disguised to resist analysis.

SEO fraud website compromise phishing Brazil Linux malware

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.