"These government systems are part of the delivery chain, not confirmed campaign targets," ANY.RUN wrote in a July 16 report describing hijacked .gov.br portals.
Who is running the redirects: Gambling Goblin and Earth Berberoka
Security researchers have attributed a multilingual campaign of search-engine abuse and redirection to a Chinese-speaking cluster that Check Point Research calls Gambling Goblin. Check Point has tracked the campaign since mid-2025 and tied the cluster to Earth Berberoka, an actor Trend Micro documented in 2022. The public reporting links the activity to parallel phishing networks localized in Vietnamese, Spanish and English and to infrastructure that generates new domains daily.
Technique: malicious Apache modules that reverse-proxy trusted domains
At the heart of the operation are malicious Apache modules installed on compromised web servers—many hosted under Brazilian government (.gov.br) and judicial (.jus.br) domains, plus educational institutions. The modules reverse-proxy visitors so that traffic appears to come from the legitimate domain while serving attacker-controlled phishing pages. Those pages mimic trusted app stores, including Google Play, Microsoft Store and Amazon, and then push online gambling and sports betting behind that facade.
Check Point noted the modules also strip the site's security headers so the injected content can run freely, and said the operators are "one step from pushing malware straight to victims." The actors appear focused on search engine optimization (SEO) manipulation at scale: chaining high-reputation domains together to inflate search rankings for gambling-related content.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTools found on compromised hosts
Once on a host, Check Point observed deployment of an array of tools and implant families: DownPro (a custom downloader), AlphaAgent (a modular backdoor), oRAT (a remote access trojan), a 3snake-based credential stealer, an SSH brute-forcer and a plugin-driven reconnaissance agent. The public version of 3snake attaches ptrace to newly spawned sshd and sudo processes and extracts strings related to password-based authentication; its documentation states the tool targets rooted servers. The Hacker News reviewed the 3snake source on GitHub on September 2, 2026 and confirmed those behaviors.
Check Point has not directly observed how the group obtains initial access. An exposed open directory on one of the actor's servers held an ELF binary written in Go bundling reconnaissance and scanning plugins. The published material so far includes no count of compromised servers and no module filenames, paths or hashes that would let administrators check their Apache instances.
Parallel activity on IIS and the wider delivery chain
Similar SEO and redirection techniques have been observed on Microsoft Internet Information Services (IIS) servers. ESET reported in June 2025 that at least 65 Windows servers—mainly in Brazil, Thailand and Vietnam—were compromised by an actor dubbed GhostRedirector, which installed a native IIS module called Gamshen that performs SEO fraud. Gamshen altered responses only when the request came from Googlebot, leaving ordinary visitors with the legitimate page. Palo Alto Networks Unit 42 documented the same reverse-proxy technique on IIS servers in September 2025.
Independent telemetry shows the scale of the problem. Hunt.io said in July 2025 it had found more than 630,000 URLs generated on hijacked gov.br subdomains, serving keyword-stuffed government-style pages to Googlebot while redirecting real users to betting sites. Hunt.io redacted certain indicators in coordination with Brazil's government incident response team, CTIR, while that investigation continued. "The goal was not to break into systems. It was to control visibility," the company said.
What this means for security teams, CTIR, and end users
- Security teams and technologists should be aware that compromised high-reputation domains can be weaponized for large-scale SEO fraud without changing the visible page for ordinary visitors; searching for unusual Apache modules, stripped security headers and reverse-proxy behavior is the relevant signal described by Check Point and others.
- Brazil's CTIR and municipal incident responders face a delicate choice: blocking hijacked .gov.br hosts broadly risks disrupting public services, while leaving them available preserves the actors' delivery chain. ANY.RUN explicitly recommended handling compromised .gov.br and .jus.br hosts separately from attacker-controlled infrastructure.
- End users and online shoppers should know that promoted gambling or app-download pages may be served through legitimate government domains; Check Point did not say whether the betting sites promoted through the compromised servers hold the authorizations that Brazil began issuing for fixed-odds betting on January 1, 2025 under Law 14,790/2023.
The public reporting links multiple clusters—Gambling Goblin/Earth Berberoka, GhostRedirector and others—using similar module-based SEO fraud and reverse-proxy tricks. What remains unresolved in the published material is the number of compromised servers, the specific module artifacts that would enable rapid detection, and whether the affected servers have been cleaned. For now, defenders and incident responders must weigh the operational trade-offs of blocking abused government subdomains against preserving access to public resources.




