An organization known as Gambling Goblin, which is a Chinese-speaking cybercrime group, has compromised Apache web servers owned by Brazilian government agencies and educational institutions, redirecting legitimate web visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research has been monitoring the activity since mid-2025.
Attackers install rogue Apache modules on the web server and utilize them to reverse proxy selected visitors to external web sites. While the destination is controlled by the attackers, the traffic appears to originate from a legitimate domain, making it harder to identify the activity.
It is designed to mimic trusted platforms like Google Play, Microsoft Store, and Amazon in order to facilitate identification of malicious sites.
These familiar interfaces direct visitors to phishing sites, online gambling or sports betting services. Researchers believe that this campaign is primarily the result of SEO manipulation.
It has been shown that operators are capable of exploiting trust associated with government and institutional domains by compromising high-reputation websites and serving or proxying attacker-controlled content in order to increase the visibility of gambling-related pages in search results by exploiting the trust associated with those domains.
This campaign also demonstrates a broader trend in web-server compromises.
Instead of defacing websites or uploading malicious files, attackers are altering the Apache environment directly, giving them greater control over how requests are handled as well as allowing compromised domains to participate in a wider network of delivery and redirection.
Malicious Apache Modules Give Attackers Deeper Control
Modules within the Apache web server provide malicious modules access to request and response handling. These attacks may allow attackers to inspect incoming traffic, alter responses, redirect selected requests, and proxy content from external infrastructure by inspecting incoming traffic, altering responses, or redirecting selected requests.
Researchers observed that the modules removed security headers from compromised sites prior to serving or proxying attacker-controlled pages as part of the Gambling Goblin campaign.
During the change, security controls that would prevent the execution of injected or redirected content may be weakened. As a result of the selective nature of the activity, detection becomes more difficult.
Even when specific requests, crawlers, or targeted traffic receive manipulated content, the compromised website may continue to operate normally for most visitors. This allows the legitimate site to remain functional while the attacker's infrastructure is quietly utilized to carry out his or her operations.
A Broader Toolkit Supports the Campaign
The Apache modules appear to be only one part of Gambling Goblin’s infrastructure. Check Point researchers also identified a scanning component called cam-agent on exposed systems, which is used to gather information about internet-facing infrastructure and identify potential targets.
After gaining access, the attackers can deploy additional tools through DownPro, a loader capable of retrieving payloads such as the ChUser backdoor, AlphaAgent and oRAT. The toolkit also includes utilities for testing SSH credentials, giving the operators multiple ways to maintain access and move further into compromised environments.
AlphaAgent provides remote command execution, file transfers and tunneling capabilities, while also searching for SSH keys and shell history.
The malware can be disguised as a legitimate system service to reduce suspicion. oRAT similarly establishes persistence through a service designed to resemble a normal firewall-related component.
The infrastructure supporting the operation is also built for resilience. Researchers observed the use of newly created domains to replace infrastructure that becomes blocked or unavailable. Encryption, disguised processes and memory-based payload handling further complicate analysis and detection.
Government Domains Used for Search Manipulation
A campaign's use of government and education websites provides additional benefits beyond its initial compromise. Established public domains are more reputable with search engines and can provide greater visibility for web pages hosted or proxied through them. This infrastructure was used by researchers at Check Point to present fake application-download pages in Chinese, Vietnamese, Spanish and English, as well as gambling and fraud applications.
As indicated by the usage of multiple languages, the operation does not focus on a single region. A separate report from ANY.RUN published in July identified that at least twenty Brazilian municipal and police portals had been utilized to distribute malware in a campaign known as PhantomEnigma, which included at least 20 gov.br portals belonging to municipalities and police departments.
As a result of the
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article: