Key Findings A Chinese-speaking threat actor, which CPR has dubbed “Gambling Goblin,” is compromising trusted government websites and turning them into infrastructure for a fraud operation built to scale The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor The phishing pages impersonate Google Play, Microsoft Store, and Amazon, complete with fake ratings and reviews, and are used to push online gambling and sports betting The group is linked to Earth Berberoka, a […]
Read the original article: