Key Findings

  • A Chinese-speaking threat actor, which CPR has dubbed “Gambling Goblin,” is compromising trusted government websites and turning them into infrastructure for a fraud operation built to scale
  • The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor
  • The phishing pages impersonate Google Play, Microsoft Store, and Amazon, complete with fake ratings and reviews, and are used to push online gambling and sports betting
  • The group is linked to Earth Berberoka, a previously documented cluster that targeted gambling sites across Asia, tying this to a decade-long pattern of gambling-driven cyber crime now being redirected and exported to new regions

A Fraud Model Built to Scale and Already Exporting

Check Point Research has been tracking a sustained campaign, active since mid-2025, that marks a real shift in how and where cyber crime targets trusted infrastructure. The group behind it, which CPR dubbed, “Gambling Goblin”, is a Chinese-speaking cybe rcrime cluster tied to Earth Berberoka, previously documented targeting gambling sites across Asia. Its playbook: compromise trusted, high-reputation web servers and turn them into infrastructure for a global SEO fraud operation.

Brazil is where that playbook is most advanced today, a shift from the home-grown banking-trojan crews that have historically dominated the region, and a sign that a decade of gambling-sector cyber crime is now moving into new markets. But Check Point Research found the same template already localized for Vietnamese, Spanish, and English-speaking audiences, with infrastructure generating fresh domains daily signaling that it’s a model built to travel.

Turning Trusted Servers Into Invisible Doors

Once inside a host, Gambling Goblin deploys a broad, heavily obfuscated Linux toolkit, a custom downloader, several backdoors, a credential stealer, and a reconnaissance agent for mapping internet-facing infrastructure.

The real purpose shows up at the network layer. The group installs custom Apache modules on compromised servers that quietly proxy visitors to attacker-controlled phishing pages — without ever showing a foreign domain in the browser bar. The modules also strip the server’s security headers, clearing the way for injected scripts to run unrestricted. The effect: a trusted, reputable server becomes a stealthy front door.

Borrowed Reputation, Manufactured Rankings

The phishing pages are built to fool people and search engines alike, impersonating Google Play, Microsoft Store, and Amazon, complete with fabricated ratings and structured metadata, while actually pushing online gambling and sports betting.

In Brazil, app tiles and navigation links on these pages point to dozens of real domains. The majority of examples found impersonate legitimate .gov.br government sites spanning federal, state, and municipal institutions. By chaining together domains that already carry high search reputation, the operators borrow that trust to push gambling content up the rankings and hijack the traffic that follows. Investigators also traced generated domains back to gambling and adult-content sites aimed at Chinese-speaking audiences and found infrastructure overlaps, including a shared Amazon ASN previously tied to Earth Berberoka.

Why This Matters

This campaign shows a patient, industrialized abuse of institutional trust, carried out with tooling more commonly associated with espionage-grade operations. It blurs the line between cybercrime and APT. And the risk doesn’t stop at SEO fraud: because the phishing pages already impersonate legitimate app stores, the same infrastructure is one configuration change away from pushing malicious apps directly to victims, in any region the operation expands to next.

What Defenders Should Do

  • Audit Apache configurations and installed modules. Look for unexpected .so files, especially any timestamped to match legitimate modules like mod_ssl or mod_suexec.
  • Watch for stripped security headers. A sudden absence of Content-Security-Policy headers on specific URL paths is a strong signal of injected reverse-proxy behavior.
  • Public-sector organizations should treat domain reputation as an asset to defend. A compromised .gov domain doesn’t just harm its own users — it can be weaponized to launder trust for fraud aimed at millions of others.
  • Security teams should hunt for masqueraded processes and rogue Apache modules, not just malware on endpoints.

For the full technical breakdown, including IOCs, read the complete Check Point Research report.

 

You may also like