Gambling Goblin Backdoors Apache on Brazil Gov Sites

A Chinese-speaking cybercrime group dubbed Gambling Goblin is hijacking traffic from Brazilian government and university websites by installing malicious Apache modules on compromised servers and silently redirecting visitors to online gambling and sports betting pages.[1][2][12]

Researchers at Check Point say they have tracked the campaign since mid-2025, with victims concentrated among federal, state and municipal agencies as well as public education institutions in Brazil.[1][2][12]

The attackers compile custom Apache HTTP Server modules and load them into already compromised web servers, turning the legitimate infrastructure into covert reverse proxies under their control.[1][2]

From the user’s perspective the domain in the address bar remains a trusted .gov.br or .edu.br site, but their requests are transparently proxied to attacker-controlled pages that promote gambling apps and betting platforms.[1][2][5]

To maximize the reach of their injected content, the modules strip or weaken security headers set by the original sites, allowing scripts and iframes on the malicious landing pages to execute without the usual browser-enforced protections.[1][2]

Many of these landing pages impersonate app marketplaces such as Google Play, Microsoft Store and Amazon to lend an air of legitimacy to the gambling offers.[1][2][5]

Check Point’s analysis describes the primary goal of Gambling Goblin as search engine optimization abuse rather than direct network intrusion or ransomware deployment.[1][12]

By chaining together a large number of compromised, high-reputation government and educational domains, the group inflates the search rankings of its gambling pages and hijacks organic traffic at scale.[1][2][12]

Separate research into SEO poisoning on Brazilian government infrastructure has already shown how extensive such abuse can be, with one 2025 investigation alleging that more than 630,000 .gov.br subdomains were hijacked in a large-scale scam operation, underscoring the attractiveness of these domains to fraudsters even when they are not linked to Gambling Goblin.[14]

Check Point attributes the campaign to a Chinese-speaking cybercrime cluster it tracks as Gambling Goblin, which it links to the previously documented Earth Berberoka group that targeted gambling sites across Asia.[1][12]

Public reporting links the two operations on the basis of observed operational similarities, though full technical details of the overlap have not been released.[1][12]

While the campaign’s infrastructure and lure content indicate a profit-driven operation, the use of stealthy server-side modules and high-profile government domains gives it an impact more commonly associated with advanced persistent threat actors.[1][2][12]

Public reports on Gambling Goblin’s activities have not yet tied the intrusions to any specific Apache HTTP Server vulnerability, leaving open whether initial access came from stolen credentials, web shell reuse or exploitation of older flaws.[1][12]

Apache environments remain a high-value target, however, and long-known issues such as the path traversal and remote code execution vulnerabilities CVE-2021-41773 and CVE-2021-42013 in Apache 2.4.49 and 2.4.50 continue to appear in exploitation reports and in the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.[4][8]

The Apache Software Foundation’s security advisories also list a steady stream of flaws affecting the 2.4.x branch, including recent issues in modules such as mod_http2 and mod_proxy, while vendor bulletins highlight that eight Apache HTTP Server CVEs were fixed in version 2.4.64 released in July 2025.[9][10][11]

Administrators running public-facing Apache HTTP Server instances, particularly on government and higher-education domains, should assume they are attractive targets for traffic-hijacking and SEO abuse campaigns like Gambling Goblin’s.[1][2][12]

Security teams are advised to audit all loaded Apache modules, compare them against known-good baselines from their distributions, and investigate any unfamiliar or unsigned components embedded in the web server stack.[1][2]

Log analysis for anomalous reverse-proxy behavior, unexpected redirects to gambling or betting content, and sudden spikes in outbound connections from web servers can help uncover compromise even when the front-end content appears normal.[1][2]

Keeping Apache patched to current versions, monitoring CISA’s Known Exploited Vulnerabilities list for actively abused HTTP Server CVEs, and hardening access to administrative interfaces remain critical to reducing the attack surface for both this and future campaigns.[8][9][10]

References

  1. Gaming the system: how a Chinese-speaking actor turned …
  2. Maliziöse Apache-Module kapern brasilianische Behörden-Websites für Glücksspiel-Phishing
  3. Vulnerabilidade no Apache HTTP Server permite instalação do …
  4. The Hacker News (@TheHackersNews) / X
  5. Known Exploited Vulnerabilities Catalog | CISA
  6. Apache HTTP Server 2.4 vulnerabilities
  7. 8 CVEs Fixed in Apache HTTP Server July 2025 Update
  8. Information on source package apache2 – Security Bug Tracker
  9. Infosecurity Magazine – Information Security & IT Security News and Resources
  10. Brazilian gov sites hijacked for scam operation – LinkedIn

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply