Executive Summary
The Chinese-speaking Gambling Goblin cybercrime cluster has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules to redirect visitors to attacker-controlled gambling and sports betting pages. The campaign leverages compromised high-reputation .gov.br domains to manipulate search engine optimization at scale, with modules reverse-proxying traffic while stripping security headers to allow malicious content execution. Linked to the Earth Berberoka threat group, the operation deploys sophisticated tooling including custom downloaders, modular backdoors, and credential stealers to maintain persistent access to government infrastructure.
This incident highlights the growing trend of SEO manipulation attacks targeting government domains for cybercriminal profit, particularly as Brazil's newly regulated online betting market creates lucrative opportunities for threat actors to exploit trusted infrastructure for financial gain.
Why This Matters Now
Government domain hijacking for SEO manipulation represents an escalating threat as cybercriminals increasingly target trusted infrastructure to bypass security controls and exploit legitimate reputation for financial schemes, requiring immediate attention to web server security posture.
Attack Path Analysis
The Gambling Goblin threat group compromised Brazilian government web servers through unknown initial access methods, then deployed multiple malicious tools including custom Apache modules to hijack visitor traffic. They established persistence using backdoors like AlphaAgent and oRAT, moved laterally across government infrastructure using SSH brute-forcing and credential theft via 3snake, maintained command and control through reverse-proxy techniques and custom malware, exfiltrated credentials and system information while redirecting legitimate traffic to gambling sites, ultimately achieving widespread SEO manipulation impact affecting over 20 .gov.br domains.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers gained unauthorized access to Brazilian government web servers through unspecified methods, likely exploiting web application vulnerabilities or using compromised credentials to install malicious Apache modules
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
Modify Registry
OS Credential Dumping: /etc/passwd and /etc/shadow
Brute Force: Password Guessing
Proxy
Phishing: Spearphishing Link
Process Injection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – System Components Protected from Known Vulnerabilities
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Network and Environment
Control ID: 5.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
NIST SP 800-53 – Malicious Code Protection
Control ID: SI-3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Brazilian government sites compromised via malicious Apache modules enabling traffic hijacking to gambling sites, exposing critical infrastructure to web server exploitation and SEO manipulation attacks.
Higher Education/Acadamia
Educational institutions targeted alongside government entities through Apache module compromise, creating reputational damage while enabling attackers to leverage trusted domains for malicious traffic redirection.
Internet
Web hosting and internet infrastructure providers face Apache server compromise risks through malicious modules, enabling reverse-proxy attacks and unauthorized content injection affecting client domains.
Gambling/Casinos
Legitimate gambling operators impacted by SEO manipulation campaigns using compromised government sites to artificially promote unauthorized betting platforms, undermining market integrity and regulatory compliance.
Sources
- Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pageshttps://thehackernews.com/2026/09/malicious-apache-modules-hijack.htmlVerified
- Gaming the System: How a Chinese-Speaking Actor Turned Brazilian Government Sites Into an SEO Weaponhttps://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/Verified
- New APT Group Earth Berberoka Targets Gambling Websites with Old and New Malwarehttps://www.trendmicro.com/en_us/research/22/d/new-apt-group-earth-berberoka-targets-gambling-websites-with-old.htmlVerified
- GhostRedirector: Poisons Windows Servers with Backdoors and Side Potatoeshttps://www.welivesecurity.com/en/eset-research/ghostredirector-poisons-windows-servers-backdoors-side-potatoes/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the Gambling Goblin's lateral movement and command & control capabilities across Brazilian government infrastructure. The segmented network architecture would likely have reduced their blast radius from 20+ compromised domains to isolated workload clusters.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero trust architecture would likely have limited the initial compromise scope by restricting unauthorized access to web server infrastructure through identity-aware access controls and workload isolation policies.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation policies would likely have constrained the backdoor's ability to obtain elevated privileges by isolating workloads and restricting administrative access paths between server components and system processes.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly reduced lateral movement by blocking unauthorized SSH connections between government domains and constraining credential-based access to segmented network zones across the infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained the reverse-proxy communications by monitoring anomalous traffic patterns and blocking unauthorized outbound connections from compromised web servers to external command infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained credential exfiltration by monitoring and restricting outbound data flows from compromised servers, limiting the attacker's ability to transmit stolen authentication data and reconnaissance information externally.
The constrained lateral movement and reduced blast radius would likely have limited the impact to isolated workload clusters rather than widespread compromise across 20+ government domains and educational institutions.
Impact at a Glance
Affected Business Functions
- Public Citizen Services
- Government Portal Services
- Educational Institution Operations
- Law Enforcement Digital Services
Estimated downtime: N/A
Estimated loss: N/A
Compromised web server infrastructure used for SEO manipulation and traffic redirection to gambling sites. Government domain reputation compromised. Potential credential theft from administrative accounts via 3snake credential stealer targeting SSH and sudo processes.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between government systems and limit blast radius of compromised servers
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections to gambling sites and detect malicious traffic redirection attempts
- • Enable Multicloud Visibility & Control to monitor anomalous web server behavior, detect reverse-proxy installations, and identify suspicious module modifications
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal Apache module behavior and alert on unauthorized credential extraction activities
- • Deploy Inline IPS (Suricata) to detect and block known malicious payloads associated with Gambling Goblin tools like oRAT, AlphaAgent, and 3snake credential stealers



