Malicious Apache Modules Exploit Brazilian Government Websites to Redirect Traffic to Gambling Sites
A Chinese-speaking cybercrime group, Gambling Goblin, deployed malicious Apache modules on Brazilian government and educational servers to redirect traffic to phishing pages promoting online gambling. The attack involved SEO manipulation through compromised high-reputation domains, with tools like DownPro and oRAT used for reconnaissance and credential theft.
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting.
Check Point Research said it has tracked the campaign since mid-2025.
The modules
*** END OF TRANSMISSION ***