Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime group, linked to Earth Berberoka and previously associated with gambling website attacks in Asia, is using compromised Brazilian government and educational servers to host malicious Apache modules. These modules redirect visitors to phishing pages mimicking trusted app stores (Google Play, Microsoft Store, Amazon) and promote online gambling and sports betting, primarily through SEO manipulation. The group employs tools like DownPro, AlphaAgent, and an oRAT to maintain control over compromised systems and steal credentials. The campaign is linked to a broader effort to control visibility and manipulate search rankings.
A Chinese-speaking cybercrime cluster, linked to Earth Berberoka and previously associated with gambling website attacks in Asia, is leveraging compromised Brazilian government and educational servers to host malicious Apache modules. These modules redirect visitors to phishing pages mimicking trusted app stores, including Google Play, Microsoft Store, and Amazon, and push online gambling and sports betting behind that facade. The group, known as Gambling Goblin, employs tools like DownPro, AlphaAgent, and an oRAT to maintain control over compromised systems and steal credentials. The campaign is linked to a broader effort to control visibility and manipulate search rankings.
Check Point Research has tracked the campaign since mid-2025, noting that the modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain. The site's own security headers are stripped, allowing the injected content to run freely. The group uses a 3snake-based credential stealer and an SSH brute-forcer to further enhance their control.
Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023, and authorized operators to run on .bet.br domains issued through Registro.br, Brazil's domain registry. Check Point did not say whether the betting sites promoted through the compromised servers hold that authorization.
Parallel phishing networks localized in Vietnamese, Spanish, and English were also identified, along with infrastructure that generates new domains daily. The goal was not to break into systems; instead, the operators aimed to control visibility and manipulate search rankings. Hunt.io found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages to Googlebot while redirecting real users to betting sites. Palo Alto Networks Unit 42 documented a similar reverse-proxy technique on IIS servers in September 2025. ESET documented at least 65 Windows servers, mainly in Brazil, Thailand, and Vietnam, compromised in June 2025 by GhostRedirector, an actor assessed with medium confidence as China-aligned, which installed a native Internet Information Services (IIS) module called Gamshen.
ESET noted that Gamshen altered the server's response only when the request came from Googlebot, leaving ordinary visitors with the page they asked for. The group is linked to Earth Berberoka, a Chinese-speaking actor Trend Micro documented in 2022 as targeting gambling websites across Asia using malware families historically attributed to Chinese-speaking individuals. Xnote, a Linux backdoor tied to the group, was reported in March during attacks on critical infrastructure in Asia. The Hacker News reviewed the 3snake source on GitHub on September 2, 2026, and confirmed both. The credentials used to administer a compromised server are therefore read by a component the operators control.
