For more than a year, the Chinese-language group known as Gambling Goblin has compromised Brazilian government servers, using the high reputation of the domains to boost the search-engine rankings of the group’s phishing sites.

The attacks focus on creating a reverse-proxy network to boost the legitimacy of gambling-oriented phishing sites, increasing the sites’ rankings on search engines, according to a new report from Check Point Software Technologies. The group has compromised about 30 servers in Brazil, mainly belonging to local governments and education organizations, with a handful of companies affected as well.

While the cybercriminal group deploys Apache modules and Linux tools to compromised servers to build the proxy network, the concern is that the network could easily be used to push malware or further compromise connected networks, says Pedro Drimel Neto, malware analyst team leader at Check Point Software.

Related:‘Breeze Comet’ Tears Into Brazilian & Global Financial Systems

“Essentially, they can turn this infrastructure into anything they want at any given time,” he says. “They can even allow it to download malware at some point because the infrastructure has already been created.”

Brazil continues to be a popular Latin American target of cybercriminals. A decade ago, many operations relied on banking Trojans that stole credentials, logged into victims’ accounts, and transferred funds. Ransomware and malware have become a more popular post-compromise payload in recent years. Last year, for example, researchers at Trend Micro discovered a self-propagating Trojan that grabbed credentials and used them to steal funds, after which is forwarded itself to the victim’s other contacts on WhatsApp.

In 2025, Brazil legalized online betting, resulting in a surge of gambling activity. The country is currently considering strengthening protections for citizens, who are frequently targeted with algorithmic casino games, but illegal gambling sites are often promoted by cybercriminals.

From China, With Rootkits

The attackers appear to be connected to a well-known group, Earth Berberoka, that has used similar tactics against targets in the Asia Pacific region, according to Check Point Software’s analysis. The company found a second network, for example, that focuses on Vietnamese-speaking users. The comments throughout the code and scripts used Chinese and had frequent emojis, suggesting AI-augmented development of the tools.

The researchers have not yet identified the initial access vector used by the cybercriminals group. Yet, when Gambling Goblin gains access, they co-opt victims’ servers to compile and install a stealthy Linux toolkit, including a downloader, multiple backdoors, a credential stealers, and other post-compromise offensive programs. Check Point also observed placeholder filenames for rootkits, but the researchers didn’t detect any in the malware samples they analyzed.

Related:Interpol’s Jackal IV Disrupts West African Crime Infrastructure

The customized reverse-proxy software stealthily attaches attacker-controlled content onto a compromised web server, making it seem as if it came from a legitimate domain, according to the analysis.

“The module registers itself at Apache’s name-translation stage and inspects every incoming request for one of a small set of hardcoded URL prefixes,” the report stated. “When a request matches, the module rewrites it into a reverse-proxy request to a corresponding upstream server hardcoded into the source, silently relaying the visitor to attacker infrastructure while the request still appears, to the outside world, to come from the legitimate compromised domain.”

The extent of the compromise is still unclear, says Check Point Software’s Neto. Many of the Web servers belong to small municipal governments, which typically have limited IT teams and rarely have a dedicated cybersecurity professional. While Check Point notified the Web server owners of the compromises, they did not get much information back, he says.

Related:‘Jewelbug’ APT Balances State Espionage & Cryptocurrency Theft

“We don’t know how separate those compromised Web servers are from the government networks,” Neto says. “The could be, of course, completely separate, completely different administrators, different passwords and all that, but it could be part of the same network. We don’t know.”

Next Steps Raise Concerns

Currently, the Gambling Goblin group’s campaign is focused on creating infrastructure to boost visibility for gambling sites. Yet, the infrastructure could easily be re-tasked with goals. Check Point warned that malware distribution could be fairly simple, but the attackers’ access to the servers could be a jumping-off point into the rest of the network, especially if they are able to find additional privileged credentials.

“They could be collecting credentials that are potentially used within other [parts of the] infrastructure by those government institutions,” Neto says. “That is the part where we believe is a little bit overlooked by some of defenders — OK, it’s just phishing in a sense, but with those tools, they could collect those credentials.”

In the past, Brazilian organizations were mainly targeted by local cybercriminals groups, because the country benefitted from its heterogenous technology and business environment, Neto says.

“You saw more local groups targeting local markets in Latin America, because the mix of different technology, [difficulty in] cashing out, and also language could be also a barrier — before AI, at least,” he says.

Now, the landscape has changed. The fact that Chinese groups have begun targeting Latin America for cybercrime shows that global cybercrime syndicates are quickly growing, often helped by AI systems’ ability to natively translate phishing lures and content, he says.

“It seems to us they are preparing themselves to target other countries, but nothing in practice yet,” he says. “We are still monitoring this group and seeing how far they will go.”





Source link

#

Comments are closed