CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5553

As cited

Copy frozen at (site build).

threat intel

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

A Chinese-speaking cybercrime group dubbed Gambling Goblin, linked to the previously documented Earth Berberoka cluster, has conducted a sustained campaign against Brazilian government and educational institutions since mid-2025. The attackers compromise web servers, install malicious Apache modules to redirect traffic to phishing pages impersonating app stores, and manipulate search engine optimization to boost gambling and sports betting sites while using Brazilian government domains to inflate their legitimacy. The operation deploys a sophisticated Linux toolkit including custom downloaders, backdoors (AlphaAgent and oRAT), credential stealers, and reconnaissance scripts, with infrastructure scaled for expansion into Vietnamese, Spanish, and English-speaking markets.

Why it matters: Brazilian government administrators, educators, and any organization running exposed Linux web servers need to audit Apache configurations, patch internet-facing services, and hunt for rogue modules and process masquerading immediately; the same infrastructure currently serving phishing is one configuration change away from delivering malware to millions of mobile users. Organizations globally should watch for similar patterns in their regions, as the threat actors have built this operation to export and scale across multiple countries and languages.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

A Chinese-speaking cybercrime group dubbed Gambling Goblin, linked to the previously documented Earth Berberoka cluster, has conducted a sustained campaign against Brazilian government and educational institutions since mid-2025. The attackers compromise web servers, install malicious Apache modules to redirect traffic to phishing pages impersonating app stores, and manipulate search engine optimization to boost gambling and sports betting sites while using Brazilian government domains to inflate their legitimacy. The operation deploys a sophisticated Linux toolkit including custom downloaders, backdoors (AlphaAgent and oRAT), credential stealers, and reconnaissance scripts, with infrastructure scaled for expansion into Vietnamese, Spanish, and English-speaking markets.

Why it matters: Brazilian government administrators, educators, and any organization running exposed Linux web servers need to audit Apache configurations, patch internet-facing services, and hunt for rogue modules and process masquerading immediately; the same infrastructure currently serving phishing is one configuration change away from delivering malware to millions of mobile users. Organizations globally should watch for similar patterns in their regions, as the threat actors have built this operation to export and scale across multiple countries and languages.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

A Chinese-speaking cybercrime group dubbed Gambling Goblin, linked to the previously documented Earth Berberoka cluster, has conducted a sustained campaign against Brazilian government and educational institutions since mid-2025. The attackers compromise web servers, install malicious Apache modules to redirect traffic to phishing pages impersonating app stores, and manipulate search engine optimization to boost gambling and sports betting sites while using Brazilian government domains to inflate their legitimacy. The operation deploys a sophisticated Linux toolkit including custom downloaders, backdoors (AlphaAgent and oRAT), credential stealers, and reconnaissance scripts, with infrastructure scaled for expansion into Vietnamese, Spanish, and English-speaking markets.

Why it matters: Brazilian government administrators, educators, and any organization running exposed Linux web servers need to audit Apache configurations, patch internet-facing services, and hunt for rogue modules and process masquerading immediately; the same infrastructure currently serving phishing is one configuration change away from delivering malware to millions of mobile users. Organizations globally should watch for similar patterns in their regions, as the threat actors have built this operation to export and scale across multiple countries and languages.

VendorsAmazon Web ServicesAppleCheck PointCloudflareDockerGitHubGitLabGoogleLinuxMicrosoftTrend Micro
Actorsplay
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary