Threat Intelligence

Government and Education Websites Hijacked to Push Betting Scams

The Hacker News · 2 Sept 2026
Key Takeaway Regularly audit your web server configuration and installed modules, apply security patches promptly, and monitor for unexpected redirects to catch server-level compromises early.

Security researchers at Check Point have identified a campaign, active since mid-2025, in which a cybercrime group called Gambling Goblin has been compromising web servers belonging to Brazilian government and educational institutions. The attackers install malicious modules into the Apache web server software running these sites, allowing them to secretly redirect visitors to pages promoting online gambling and sports betting.

Because the malicious code operates at the web server level rather than through obvious pop-ups or fake links, ordinary visitors may not realise they have been redirected until they land on a suspicious betting site. For the compromised organisations, this represents a serious breach of trust and reputation, as their legitimate domains are effectively being used to funnel traffic to unrelated and potentially illegal gambling operations.

While this campaign currently targets Brazilian institutions, the technique of hijacking web server software to silently redirect traffic is not region-specific and could be adapted to target businesses anywhere, including Australian organisations running self-managed web servers. Any business running its own website infrastructure, rather than a fully managed hosting service, should treat this as a reminder to review server security regularly.

web server security malware Apache website compromise cybercrime

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.