Brazilian government websites have been quietly turned into gateways for phishing pages on trusted public domains. Rather than sending victims to obvious scam sites, attackers are using compromised web servers to make fraudulent content look legitimate immediately.

The campaign has targeted Brazilian government and education organizations since mid-2025. Operators deploy a Linux toolkit after gaining access, and use hijacked sites to promote gambling pages disguised as app-download services.

Check Point researchers identified the activity as the work of Gambling Goblin, a Chinese-speaking cybercrime cluster linked with medium-to-high confidence to Earth Berberoka.

Check Point said in a report shared with Cyber Security News (CSN) that the discovery signals a sharp change from Brazil’s largely domestic banking-trojan landscape to a foreign group exploiting public-sector trust.

Infection chain (Source – Check Point)

Trusted domains can boost malicious pages in search results, steer visitors toward fake stores, and make fraud seem official. Researchers also found similar templates in Vietnamese, Spanish, and English, suggesting an operation designed to expand.

Malicious Apache Modules

The attackers’ key tool is a custom Apache module compiled directly on an infected server. A Bash installer checks the operating system, installs the needed Apache development packages, retrieves the C source code, and uses Apache’s own tooling to build and activate the module.

To avoid raising alarms, the installer removes source and build files after deployment. It then changes timestamps on the malicious shared object and configuration files so they resemble ordinary Apache components. This makes a quick server review less likely to expose the intrusion.

One module watches for selected request paths and silently relays them to attacker infrastructure. Visitors remain on a genuine government domain but receive remote phishing content. It also removes browser content-security restrictions, allowing injected scripts and external assets to load.

CSP stripping so injected scripts can run (Source - Check Point)
CSP stripping so injected scripts can run (Source – Check Point)

A second module can inspect the path, referrer, browser details, and client address before deciding what content to display.

It can insert remote material into a web response, enabling selective cloaking and search manipulation. Similar abuse of official domains has appeared in government website phishing campaigns, where domain reputation helps criminal pages seem safe.

The pages observed in this campaign imitate Google Play, Microsoft Store, and Amazon-style download destinations. Fabricated ratings and page data help them look convincing, while the real business model appears to be gambling promotion.

Researchers did not directly observe the initial break-in, but uncovered a scanning agent called cam-agent on exposed infrastructure. It uses reconnaissance tools to map internet-facing systems. That can identify trusted web properties worth abusing.

Once inside, the group can use DownPro to fetch further payloads, including the ChUser backdoor, a password-harvesting tool, AlphaAgent, oRAT, and an SSH credential-testing utility.

Several tools use disguises, encryption, and memory-only unpacking, echoing tactics seen in Linux RAT attacks targeting developers.

AlphaAgent can run commands, move files, create tunnels, collect SSH keys and shell history, and hide under system-service names. oRAT can establish persistence through a service that mimics a legitimate firewall component.

These features support credential theft, movement inside networks, and long-term access. The infrastructure also creates new domains daily, to replace blocked locations.

Several phishing pages (Source - Check Point)
Several phishing pages (Source – Check Point)

The report connects its tooling, Chinese-language artifacts, gambling focus, and lookalike-domain behavior to Earth Berberoka. Readers tracking this pattern can compare it with Brazilian government malware delivery and AI-driven phishing site cloning.

Public-sector and education administrators should urgently patch exposed services, review Apache modules and configuration changes, and audit SSH access for weak credentials or unusual login attempts.

They should investigate unfamiliar libraries, altered timestamps, proxy rules, and disguised processes. Administrators should compare loaded modules with approved baselines and verify that each reverse-proxy rule supports a legitimate application.

Teams should preserve logs before cleanup, reset exposed credentials, and inspect nearby systems across their environment for related tools.

The immediate campaign centers on search fraud and gambling traffic, but its fake app-store pages could easily deliver malware.

Organizations must treat a trusted domain as a possible victim, not automatic proof that a page is safe, and monitor public servers accordingly.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-256 232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017 Malware sample hash
SHA-256 088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815 Malware sample hash
SHA-256 88544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0 Malware sample hash
SHA-256 9d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdb Malware sample hash
SHA-256 263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31 Malware sample hash
SHA-256 12af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120d Malware sample hash
SHA-256 5af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611 Malware sample hash
SHA-256 e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052 Malware sample hash
SHA-256 fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288d Malware sample hash
SHA-256 c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98f Malware sample hash
SHA-256 2567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91 Malware sample hash
SHA-256 1829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020a Malware sample hash
SHA-256 f025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcf Malware sample hash
SHA-256 5a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8 Malware sample hash
SHA-256 0d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7 Malware sample hash
SHA-256 5f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710 Malware sample hash
SHA-256 c4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d4f69 Malware sample hash
SHA-256 c3c6ab58514cd13638cf049332186ef6d4ec7b256913edb1cd66a19437608882 Malware sample hash
SHA-256 582ecca146a6aef478706e4b2774d6115a9220a18d1db8f92ee54a5118ecebd9 Malware sample hash
SHA-256 3a8f464f1f2b5c38173e2a96f95a690af327d85c13c04d37cf0a91893d487bdb Malware sample hash
SHA-256 02f5e07dd4c97a3de48cc886f46dad35443f1c221a352630e2c7787806ee21b6 Malware sample hash
SHA-256 16d35a725819142d2bd5bc0949dc518d344d6f63626a517e67fcba7322eb3844 Malware sample hash
SHA-256 a71498bfffae8ac694356b3f2436820b396946c9e71c8915e282c1b2fdba4162 Malware sample hash
SHA-256 d138d5f4fbc77650bc3be1cbf8fbd0ee292aa30eed5feec1ea7ba02e57da932b Malware sample hash
SHA-256 44373953431d7570d9585c91377dbe8b6527ccc00662d249f383b003b68b459f Malware sample hash
SHA-256 45b9382d7e91a4178b47c908b9b5f6884de7c5a1ef849fbf01d6c23d06d81b88 Malware sample hash
SHA-256 1eb40363a64e0cad15e340af476d106ccf57ebb6662c1389da1347429ee68c9c Malware sample hash
SHA-256 fc789397742aee60b01292b071f79b4165981c31aa431eb1577a47c5911381c3 Malware sample hash
SHA-256 adbee84e9a43949b0a816f052ffb3c0b7855e078b985fea95532158c3b9389bc Malware sample hash
SHA-256 0f26e1ba39ddd1f0a7e6f72bd8c4e02a5f0140de72eeda9fe5ab56402821e31e Malware sample hash
SHA-256 ab7d531d298f0d77bc7bbbdc36f4f8a1732ceca90ff60e3f225a99b9b10f334e Malware sample hash
SHA-256 ac99754357bd4a69c1de576977e0ee19c7354f29f7f52a9893b7a60f9c2f5248 Malware sample hash
SHA-256 94aa88ff6222583b2a5b791ddd655837787e31f59483ed91f860857d3399b84a Malware sample hash
SHA-256 3ad35ea116b2c0855c13459a04699318b3944762385e8a47144f1d03b48f0bb1 Malware sample hash
SHA-256 0611c153bf8b8561ef53f2a5ba1413115bdc0e4554e0c22cf9641bd8845db03e Malware sample hash
SHA-256 114824bccfafcbb42040f119fdcd3ec48f54eb154ffee6676d06986cba2b0af0 Malware sample hash
SHA-256 297c53d935c501864e15fe7abcfdafed83df9aafdf241094604ae405529c5eb7 Malware sample hash
SHA-256 0963c0034a5e0665729d686d50c5375948c4a684c56770adb13d24ff5df8013d Malware sample hash
SHA-256 749784fb7846bb3b52dd8c2f660b53d95d5df30387b87b65b584ef9cc781ae52 Malware sample hash
SHA-256 8495598b1fec814d72caf76f1460b132071bb7305335331fed3bac9876c6e40c Malware sample hash
SHA-256 98e17fe36ff77106bbbb9a04f3e00004bf872b88aab22438076966913ea83322 Malware sample hash
SHA-256 bcd7e5964630c34f06a43e48d696d99d7abae6b679509ad839ffa5179a972838 Malware sample hash
SHA-256 24f7296ac5ce844678c5f7470eaf64b28e870108ca06851c8f66a27a52003f12 Malware sample hash
SHA-256 2de964314a8aacc40897140f6fe21d268e24503a69f9821177e31bca7b1e4035 Malware sample hash
SHA-256 52863d36a216a86b2f90914db2d9229cba7ea317ab5ee9a678cb229087f04611 Malware sample hash
SHA-256 9d513a419bf129a42017b29eb7d084451a4f34be0828f6871439ec79f7f9b5fb Malware sample hash
SHA-256 d478f867512e18d839180ceafc980c8fb26c3aa7d1c9e96d054819c81afef6f4 Malware sample hash
SHA-256 b88a7f3288bdf4b97d75dad4e47e5cb3d4e0962b12674a08e32e5f96e762e877 Malware sample hash
SHA-256 f4aceaf5c0740093f8040f5e0f29c7582a1bd7ab2bca628d162fb45c29045063 Malware sample hash
SHA-256 2305ae23ea350e31b05b9f071d315ee60c5a88e96ce11be8ff9db16314a6197c Malware sample hash
SHA-256 99b5404df81992cad104dd242bc736d75fd6c58af34dc1cbf8a75a8ee3c5e1784fa4 Malware sample hash
SHA-256 85b5e95cbb5103202abebf8f84b91a286994e61b33ddef53355ab0df2a2b6d9a Malware sample hash
SHA-256 cff25a9c84c893e32a9a75c1dae385934cf917f709efa11172a53ea2337fa109 Malware sample hash
SHA-256 154c977a113ff4d94ff2f29f7b93a8d0bd6ad8e67a820c09505117f5d386fd40 Malware sample hash
SHA-256 67ccc12c0a17dc31388a8c851d076edaaf1213e80398b01d46f5a29b8c7b8b9b Malware sample hash
SHA-256 e8bc706b0b007d6a122c6b19e87451e550baee793540774db13b9a08803ed76a Malware sample hash
SHA-256 f32dfbe4a2c11a975d735297bf76f6497ce9f5789ab8eaaef3fdd182c2f1f7b1 Malware sample hash
SHA-256 c59ebe5cf45935c7b5f91b5936fe2c8a5feb7ca161e40ca4e3fb93e447373fa6 Malware sample hash
SHA-256 3537bfeaf2c18feafeaf773700a88118fd50979d97f2c42c7e34ba6c9aa62820 Malware sample hash
SHA-256 2949f0b16b83b35dc8a3dfa11815b9516403e3997e13100e7b86f3bb81f6c283 Malware sample hash
SHA-256 0e7c96a22e3612c68866a8693cc583df95972d3444978ce163c024a45682133a Malware sample hash
SHA-256 7d9f5eb3f704607e6f63681842f48071cc58f2f2e63b16b64a49440cb4b9e6e3 Malware sample hash
SHA-256 8a64d368ce14c5a1f5e775714bcc02f080d0541360743bb4235e0d640f1787b1 Malware sample hash
SHA-256 36cf87fe2e29cc8b0fd84fce91d70e62a4c4d2fc5f9650dc37440d629ae61b8f Malware sample hash
SHA-256 090e886e5605255ad5708e1f27aecc54319de835abd28853e54182981410707e Malware sample hash
SHA-256 fa7d8c44a0ecb5ec40832d0d2cfe22c47879317177eae88d178e156f1c8d61a3 Malware sample hash
SHA-256 d948b486c740b66642a5ae29dc1cb80da703ad40296bcda34a1b27216b63a5cd Malware sample hash
SHA-256 612fe3a3ace706725aa5415a1cd1cf18548627b4b40636c5443cb770def30b4c Malware sample hash
SHA-256 96488c59287889fcd3b9952ec78b78914fabb901c8b61a7354552439170ed148 Malware sample hash
Domain rb[.]aliyuntsl[.]com Command-and-control or campaign infrastructure
Domain br[.]team-c2[.]com Command-and-control or campaign infrastructure
Domain hwlocal[.]team-hw[.]com Command-and-control or campaign infrastructure
Domain br[.]team-hw[.]com Command-and-control or campaign infrastructure
Domain data[.]mirrors-inc[.]com Command-and-control or campaign infrastructure
Domain team-hw[.]com Command-and-control or campaign infrastructure
Domain update[.]team-c2[.]com Command-and-control or campaign infrastructure
Domain devops[.]aliyuntsl[.]com Command-and-control or campaign infrastructure
Domain bageyi[.]kernel-lib[.]com Command-and-control or campaign infrastructure
Domain 8yiu[.]kernel-lib[.]com Command-and-control or campaign infrastructure
Domain dnslog[.]kernel-lib[.]com Command-and-control or campaign infrastructure
Domain js[.]ai-jquery[.]com Command-and-control or campaign infrastructure
Domain api[.]onlinevrgame[.]com Command-and-control or campaign infrastructure
Domain file[.]ijjjst23m[.]com Command-and-control or campaign infrastructure
Domain kerneltty[.]com Command-and-control or campaign infrastructure
Domain 80[.]443[.]team Command-and-control or campaign infrastructure
Domain up[.]443[.]team Command-and-control or campaign infrastructure
Domain 404[.]443[.]team Command-and-control or campaign infrastructure
Domain data[.]windows-update-cdn[.]com Command-and-control or campaign infrastructure
Domain microsoft-azure-loadbalance[.]com Command-and-control or campaign infrastructure
Domain update[.]aliyun[.]la Command-and-control or campaign infrastructure
Domain api[.]gitlab[.]bet Command-and-control or campaign infrastructure
Domain github[.]la Lookalike campaign domain
Domain update[.]opentls2[.]com Command-and-control or campaign infrastructure
IP Address 154[.]84[.]62[.]160 Campaign infrastructure
IP Address 154[.]84[.]62[.]128 Campaign infrastructure
IP Address 154[.]84[.]62[.]149 Campaign infrastructure
IP Address 154[.]84[.]62[.]145 Campaign infrastructure
IP Address 15[.]228[.]251[.]82 Campaign infrastructure
IP Address 56[.]124[.]87[.]60 Campaign infrastructure
IP Address 18[.]229[.]255[.]14 Campaign infrastructure
IP Address 18[.]166[.]208[.]57 Campaign infrastructure
IP Address 18[.]228[.]136[.]28 Campaign infrastructure
IP Address 43[.]198[.]248[.]193 Campaign infrastructure
IP Address 43[.]199[.]133[.]195 Campaign infrastructure
IP Address 18[.]166[.]243[.]179 Campaign infrastructure
IP Address 18[.]164[.]116[.]24 Campaign infrastructure
IP Address 13[.]203[.]9[.]172 Campaign infrastructure
IP Address 43[.]198[.]30[.]170 Campaign infrastructure
IP Address 18[.]162[.]210[.]53 Campaign infrastructure
IP Address 56[.]125[.]218[.]234 Campaign infrastructure
IP Address 18[.]228[.]195[.]216 Campaign infrastructure
IP Address 56[.]124[.]49[.]89 Campaign infrastructure
IP Address 54[.]207[.]196[.]189 Campaign infrastructure
IP Address 165[.]22[.]101[.]200 Campaign infrastructure
IP Address 172[.]80[.]8[.]202 Campaign infrastructure
IP Address 104[.]206[.]37[.]134 Campaign infrastructure
IP Address 108[.]187[.]28[.]158 Campaign infrastructure
IP Address 202[.]146[.]222[.]18 Campaign infrastructure
IP Address 192[.]253[.]229[.]23 Campaign infrastructure
IP Address 16[.]162[.]255[.]92 Campaign infrastructure
IP Address 13[.]250[.]18[.]158 Campaign infrastructure
IP Address 18[.]163[.]182[.]231 Campaign infrastructure
IP Address 204[.]16[.]172[.]106 Campaign infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.