The record
Written from the 1 report below. Nothing here is unsourced.
- A group called Gambling Goblin is installing malicious Apache modules on Brazilian government and education web servers to redirect visitors to gambling and betting pages.
- The hijacked traffic still appears to come from the legitimate government domains, which Check Point believes is being used to manipulate search engine rankings.
- The attackers' toolkit includes a credential stealer called 3snake that can read the passwords used to administer compromised servers.
- Separately, security firms ANY.RUN, ESET, and Hunt.io have documented related campaigns affecting at least 20 Brazilian government portals and more than 630,000 hijacked gov.br URLs.
- The issue matters because Brazilian government domains are being used to lend credibility to betting sites, and it is unclear whether those sites hold Brazil's official betting authorization.
What to watch next
- Whether Check Point releases module filenames, paths, or hashes so administrators can check their own Apache servers.
- Whether the promoted betting sites hold authorization under Brazil's Law 14,790/2023 on .bet.br domains.
- Whether the operators move from SEO fraud to pushing malware directly to victims, as Check Point warns they are positioned to do.
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
ANY.RUN
1 quote · 1 outlet
“These government systems are part of the delivery chain, not confirmed campaign targets”
In the article
…inflate search rankings. ANY.RUN reported in July that at least 20 .gov.br portals belonging to Brazilian municipalities and police forces had been used to distribute malware in a campaign it tracks as PhantomEnigma. " These government systems are part of the delivery chain, not confirmed campaign targets ," ANY.RUN said in a report published July 16. Compromised .gov.br and .jus.br hosts should be handled separately from attacker-controlled infrastructure, ANY.RUN said, because blocking them broadly would disrupt access…
Coverage1
All filed from India
Named Brazil · CTIR · ANY.RUN · Check Point Research · Earth Berberoka · ESET · Gambling Goblin · GhostRedirector · Hunt.io · Palo Alto Networks Unit 42 · Trend Micro
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
