Cybersecurity Research

Chinese-Speaking Hackers Hijack Brazilian Government Sites for SEO Fraud and Phishing

Check Point Research · 2 Sept 2026
Key Takeaway Businesses, including those working with or hosting content on government-linked platforms, should monitor for unexpected redirects or unfamiliar web server modules that could indicate their site has been silently hijacked.

Check Point Research has been tracking a sustained campaign since mid-2025 against Brazilian organisations, attributed to a Chinese-speaking cybercrime group connected to Earth Berberoka, previously known for targeting gambling sites in Asia. Once inside a victim's network, the attackers deploy a broad Linux toolkit including a custom downloader, multiple backdoors, and well-known offensive security tools, all heavily disguised to avoid detection.

The real goal appears to be search engine manipulation. The attackers install custom web server modules that quietly redirect visitors from compromised, high-reputation domains, many belonging to Brazilian government sites, to a network of phishing pages. This borrows the trust and search ranking of government domains to push the attackers' content higher in search results. Researchers also found a second, similar phishing network aimed at Vietnamese victims, showing the operation extends beyond Brazil.

While the immediate purpose seems to be traffic hijacking for profit, the risk could escalate. Some phishing pages impersonate legitimate app stores such as Google Play, the Microsoft Store, and Amazon, meaning the same infrastructure could be repurposed to distribute malware directly to unsuspecting users. Researchers also uncovered an exposed tool on the attackers' infrastructure, a scanning agent used to map vulnerable internet-facing systems, suggesting a methodical approach to identifying future targets.

Linux malware phishing SEO poisoning government websites Earth Berberoka

Summarised by CISO AI from Check Point Research. We link back to every original so you can read it yourself.