Since mid-2025 a Chinese-speaking cybercrime cluster has turned compromised Brazilian government and education websites into infrastructure for a sustained SEO fraud campaign.
Gambling Goblin and links to Earth Berberoka
Check Point Research (CPR) named the cluster Gambling Goblin and said it assessed with medium-to-high confidence that the operators are connected to Earth Berberoka, a Chinese-speaking group Trend Micro documented in 2022. CPR reported overlaps in tooling, operator artifacts and infrastructure — including use of the remote-administration tool oRAT, Chinese-language strings and domains crafted to resemble trusted technology brands.
Malicious Apache modules acting as stealth reverse proxies
At the core of the campaign are custom Apache modules that covertly converted legitimate sites into traffic-steering infrastructure. CPR found modules that targeted specific URL paths and routed selected visitors from compromised servers to attacker-controlled phishing pages. Those modules could strip existing Content-Security-Policy headers and replace them with permissive settings, enabling external and dynamically generated scripts to execute in victims' browsers.
According to CPR, an installer compiled each module on the victim server, removed the source, and timestomped the resultant file so it matched legitimate Apache modules — a deliberate effort to avoid detection. The phishing landing pages impersonated Google Play, the Microsoft Store and Amazon, were localized for Brazilian users, and promoted online gambling and sports betting.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageA large Linux toolkit: DownPro, AlphaAgent, oRAT and more
Web-server manipulation was only one element of a broader Linux toolkit CPR documented. The set included the DownPro downloader; backdoors such as AlphaAgent and oRAT; a 3snake-based PasswordHarvester credential stealer; and an SSH brute-forcer. Many components were wrapped in packing and lightweight virtualization layers designed to slow analysis.
CPR also identified a reconnaissance agent that used tools including httpx, naabu, Nuclei and subfinder to map internet-facing infrastructure and enumerate services on potential targets. Functionally, AlphaAgent supported remote command execution, file transfers, tunneling and host discovery, while oRAT provided remote administration. Researchers noted an AI plugin execution path in a newer AlphaAgent build, but said the sample did not reveal the plugin’s purpose.
Scope of the compromise across Brazilian public and commercial sites
CPR documented compromises that reached federal, state and municipal government domains: a ministry, a national public agency, a state legislative assembly, courts of accounts and a state-owned utility were among the victims. Municipal administrations made up the largest share. Commercial Brazilian sites were affected as well, including local news organizations, healthcare providers and business associations.
The infrastructure extended beyond Brazil: CPR found phishing pages localized in Vietnamese, Spanish and English, and systems that generated fresh domains daily. The researchers described the campaign as a shift away from Brazil’s previously observed, home-grown banking trojans toward a foreign operator drawn by “one of the world’s fastest-growing online betting markets.”
What this means for technologists, policymakers, and affected organisations
- Technologists and security teams: CPR advised auditing Apache and SSH configurations and hunting for rogue modules and masqueraded processes. Teams should expect to look for compiled modules that have had their timestamps altered and for permissive Content-Security-Policy changes on affected web servers.
- Policymakers and regulators: The campaign signals a move from locally developed banking trojans to foreign operators exploiting a large online betting market. Regulators may need to consider how attacker interest in that market changes threat priorities for public-facing infrastructure.
- Affected Brazilian organisations (federal, state, municipal and commercial): Entities that operate public websites — including municipal administrations, the ministry and state-owned utility CPR named as affected sectors — should review webserver integrity, audit for unauthorized Apache modules, and investigate suspicious redirects to app-store impersonation pages that promote gambling.
CPR warned that the existing phishing infrastructure already imitates legitimate app stores, creating a plausible path from SEO-driven traffic to direct malware distribution. Its technical findings — custom Apache reverse-proxy modules, a multi-purpose Linux toolkit, reconnaissance tooling and multilingual phishing pages — sketch a deliberate, scalable operation rather than opportunistic defacement.
The practical next step CPR recommended is immediate operational hygiene: audit webserver modules and SSH settings, and hunt for processes and files masquerading as legitimate components. Beyond that, the case raises a targeted question left in the open facts: with daily domain generation and multilingual phishing pages already in place, will the infrastructure be used to escalate from credential theft and SEO fraud into wider malware distribution?
Source: Check Point Research report, as summarized by Infosecurity Magazine (September 2, 2026)




