Chinese-Speaking Hackers Hijack Brazilian Government Sites for SEO Fraud and Phishing
Check Point Research has been tracking a sustained campaign since mid-2025 against Brazilian organisations, attributed to a Chinese-speaking cybercrime group connected to Earth Berberoka, previously known for targeting gambling sites in Asia. Once inside a victim's network, the attackers deploy a broad Linux toolkit including a custom downloader, multiple backdoors, and well-known offensive security tools, all heavily disguised to avoid detection.
The real goal appears to be search engine manipulation. The attackers install custom web server modules that quietly redirect visitors from compromised, high-reputation domains, many belonging to Brazilian government sites, to a network of phishing pages. This borrows the trust and search ranking of government domains to push the attackers' content higher in search results. Researchers also found a second, similar phishing network aimed at Vietnamese victims, showing the operation extends beyond Brazil.
While the immediate purpose seems to be traffic hijacking for profit, the risk could escalate. Some phishing pages impersonate legitimate app stores such as Google Play, the Microsoft Store, and Amazon, meaning the same infrastructure could be repurposed to distribute malware directly to unsuspecting users. Researchers also uncovered an exposed tool on the attackers' infrastructure, a scanning agent used to map vulnerable internet-facing systems, suggesting a methodical approach to identifying future targets.