Brazilian government websites have been quietly turned into gateways for phishing pages on trusted public domains. Rather than sending victims to obvious scam sites, attackers are using compromised web servers to make fraudulent content look legitimate immediately.
The campaign has targeted Brazilian government and education organizations since mid-2025. Operators deploy a Linux toolkit after gaining access, and use hijacked sites to promote gambling pages disguised as app-download services.
Check Point researchers identified the activity as the work of Gambling Goblin, a Chinese-speaking cybercrime cluster linked with medium-to-high confidence to Earth Berberoka.
Check Point said in a report shared with Cyber Security News (CSN) that the discovery signals a sharp change from Brazil’s largely domestic banking-trojan landscape to a foreign group exploiting public-sector trust.
Trusted domains can boost malicious pages in search results, steer visitors toward fake stores, and make fraud seem official. Researchers also found similar templates in Vietnamese, Spanish, and English, suggesting an operation designed to expand.
Malicious Apache Modules
The attackers’ key tool is a custom Apache module compiled directly on an infected server. A Bash installer checks the operating system, installs the needed Apache development packages, retrieves the C source code, and uses Apache’s own tooling to build and activate the module.
To avoid raising alarms, the installer removes source and build files after deployment. It then changes timestamps on the malicious shared object and configuration files so they resemble ordinary Apache components. This makes a quick server review less likely to expose the intrusion.
One module watches for selected request paths and silently relays them to attacker infrastructure. Visitors remain on a genuine government domain but receive remote phishing content. It also removes browser content-security restrictions, allowing injected scripts and external assets to load.
.webp)
A second module can inspect the path, referrer, browser details, and client address before deciding what content to display.
It can insert remote material into a web response, enabling selective cloaking and search manipulation. Similar abuse of official domains has appeared in government website phishing campaigns, where domain reputation helps criminal pages seem safe.
The pages observed in this campaign imitate Google Play, Microsoft Store, and Amazon-style download destinations. Fabricated ratings and page data help them look convincing, while the real business model appears to be gambling promotion.
Researchers did not directly observe the initial break-in, but uncovered a scanning agent called cam-agent on exposed infrastructure. It uses reconnaissance tools to map internet-facing systems. That can identify trusted web properties worth abusing.
Once inside, the group can use DownPro to fetch further payloads, including the ChUser backdoor, a password-harvesting tool, AlphaAgent, oRAT, and an SSH credential-testing utility.
Several tools use disguises, encryption, and memory-only unpacking, echoing tactics seen in Linux RAT attacks targeting developers.
AlphaAgent can run commands, move files, create tunnels, collect SSH keys and shell history, and hide under system-service names. oRAT can establish persistence through a service that mimics a legitimate firewall component.
These features support credential theft, movement inside networks, and long-term access. The infrastructure also creates new domains daily, to replace blocked locations.
.webp)
The report connects its tooling, Chinese-language artifacts, gambling focus, and lookalike-domain behavior to Earth Berberoka. Readers tracking this pattern can compare it with Brazilian government malware delivery and AI-driven phishing site cloning.
Public-sector and education administrators should urgently patch exposed services, review Apache modules and configuration changes, and audit SSH access for weak credentials or unusual login attempts.
They should investigate unfamiliar libraries, altered timestamps, proxy rules, and disguised processes. Administrators should compare loaded modules with approved baselines and verify that each reverse-proxy rule supports a legitimate application.
Teams should preserve logs before cleanup, reset exposed credentials, and inspect nearby systems across their environment for related tools.
The immediate campaign centers on search fraud and gambling traffic, but its fake app-store pages could easily deliver malware.
Organizations must treat a trusted domain as a possible victim, not automatic proof that a page is safe, and monitor public servers accordingly.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017 |
Malware sample hash |
| SHA-256 | 088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815 |
Malware sample hash |
| SHA-256 | 88544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0 |
Malware sample hash |
| SHA-256 | 9d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdb |
Malware sample hash |
| SHA-256 | 263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31 |
Malware sample hash |
| SHA-256 | 12af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120d |
Malware sample hash |
| SHA-256 | 5af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611 |
Malware sample hash |
| SHA-256 | e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052 |
Malware sample hash |
| SHA-256 | fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288d |
Malware sample hash |
| SHA-256 | c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98f |
Malware sample hash |
| SHA-256 | 2567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91 |
Malware sample hash |
| SHA-256 | 1829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020a |
Malware sample hash |
| SHA-256 | f025520d648c7799ca5bed4a9be5bee14ac33be1f1e9b20c090c8c6319404fcf |
Malware sample hash |
| SHA-256 | 5a11ed7931fb6358846e0f3c8d69921f43f8ccade5937fc41e5c262cc49f82e8 |
Malware sample hash |
| SHA-256 | 0d4a28d5cf7b99f11ffe972abd0284d9e35b6858eeb288532a55633b3e29f9c7 |
Malware sample hash |
| SHA-256 | 5f6d112637545a2e8c1a9f260c39698852c7a22e83db5ccfc99b99d9f6274710 |
Malware sample hash |
| SHA-256 | c4d2efa57eef0c5defc4ca708ebe35832f8b543cf764beebef56fef6d36d4f69 |
Malware sample hash |
| SHA-256 | c3c6ab58514cd13638cf049332186ef6d4ec7b256913edb1cd66a19437608882 |
Malware sample hash |
| SHA-256 | 582ecca146a6aef478706e4b2774d6115a9220a18d1db8f92ee54a5118ecebd9 |
Malware sample hash |
| SHA-256 | 3a8f464f1f2b5c38173e2a96f95a690af327d85c13c04d37cf0a91893d487bdb |
Malware sample hash |
| SHA-256 | 02f5e07dd4c97a3de48cc886f46dad35443f1c221a352630e2c7787806ee21b6 |
Malware sample hash |
| SHA-256 | 16d35a725819142d2bd5bc0949dc518d344d6f63626a517e67fcba7322eb3844 |
Malware sample hash |
| SHA-256 | a71498bfffae8ac694356b3f2436820b396946c9e71c8915e282c1b2fdba4162 |
Malware sample hash |
| SHA-256 | d138d5f4fbc77650bc3be1cbf8fbd0ee292aa30eed5feec1ea7ba02e57da932b |
Malware sample hash |
| SHA-256 | 44373953431d7570d9585c91377dbe8b6527ccc00662d249f383b003b68b459f |
Malware sample hash |
| SHA-256 | 45b9382d7e91a4178b47c908b9b5f6884de7c5a1ef849fbf01d6c23d06d81b88 |
Malware sample hash |
| SHA-256 | 1eb40363a64e0cad15e340af476d106ccf57ebb6662c1389da1347429ee68c9c |
Malware sample hash |
| SHA-256 | fc789397742aee60b01292b071f79b4165981c31aa431eb1577a47c5911381c3 |
Malware sample hash |
| SHA-256 | adbee84e9a43949b0a816f052ffb3c0b7855e078b985fea95532158c3b9389bc |
Malware sample hash |
| SHA-256 | 0f26e1ba39ddd1f0a7e6f72bd8c4e02a5f0140de72eeda9fe5ab56402821e31e |
Malware sample hash |
| SHA-256 | ab7d531d298f0d77bc7bbbdc36f4f8a1732ceca90ff60e3f225a99b9b10f334e |
Malware sample hash |
| SHA-256 | ac99754357bd4a69c1de576977e0ee19c7354f29f7f52a9893b7a60f9c2f5248 |
Malware sample hash |
| SHA-256 | 94aa88ff6222583b2a5b791ddd655837787e31f59483ed91f860857d3399b84a |
Malware sample hash |
| SHA-256 | 3ad35ea116b2c0855c13459a04699318b3944762385e8a47144f1d03b48f0bb1 |
Malware sample hash |
| SHA-256 | 0611c153bf8b8561ef53f2a5ba1413115bdc0e4554e0c22cf9641bd8845db03e |
Malware sample hash |
| SHA-256 | 114824bccfafcbb42040f119fdcd3ec48f54eb154ffee6676d06986cba2b0af0 |
Malware sample hash |
| SHA-256 | 297c53d935c501864e15fe7abcfdafed83df9aafdf241094604ae405529c5eb7 |
Malware sample hash |
| SHA-256 | 0963c0034a5e0665729d686d50c5375948c4a684c56770adb13d24ff5df8013d |
Malware sample hash |
| SHA-256 | 749784fb7846bb3b52dd8c2f660b53d95d5df30387b87b65b584ef9cc781ae52 |
Malware sample hash |
| SHA-256 | 8495598b1fec814d72caf76f1460b132071bb7305335331fed3bac9876c6e40c |
Malware sample hash |
| SHA-256 | 98e17fe36ff77106bbbb9a04f3e00004bf872b88aab22438076966913ea83322 |
Malware sample hash |
| SHA-256 | bcd7e5964630c34f06a43e48d696d99d7abae6b679509ad839ffa5179a972838 |
Malware sample hash |
| SHA-256 | 24f7296ac5ce844678c5f7470eaf64b28e870108ca06851c8f66a27a52003f12 |
Malware sample hash |
| SHA-256 | 2de964314a8aacc40897140f6fe21d268e24503a69f9821177e31bca7b1e4035 |
Malware sample hash |
| SHA-256 | 52863d36a216a86b2f90914db2d9229cba7ea317ab5ee9a678cb229087f04611 |
Malware sample hash |
| SHA-256 | 9d513a419bf129a42017b29eb7d084451a4f34be0828f6871439ec79f7f9b5fb |
Malware sample hash |
| SHA-256 | d478f867512e18d839180ceafc980c8fb26c3aa7d1c9e96d054819c81afef6f4 |
Malware sample hash |
| SHA-256 | b88a7f3288bdf4b97d75dad4e47e5cb3d4e0962b12674a08e32e5f96e762e877 |
Malware sample hash |
| SHA-256 | f4aceaf5c0740093f8040f5e0f29c7582a1bd7ab2bca628d162fb45c29045063 |
Malware sample hash |
| SHA-256 | 2305ae23ea350e31b05b9f071d315ee60c5a88e96ce11be8ff9db16314a6197c |
Malware sample hash |
| SHA-256 | 99b5404df81992cad104dd242bc736d75fd6c58af34dc1cbf8a75a8ee3c5e1784fa4 |
Malware sample hash |
| SHA-256 | 85b5e95cbb5103202abebf8f84b91a286994e61b33ddef53355ab0df2a2b6d9a |
Malware sample hash |
| SHA-256 | cff25a9c84c893e32a9a75c1dae385934cf917f709efa11172a53ea2337fa109 |
Malware sample hash |
| SHA-256 | 154c977a113ff4d94ff2f29f7b93a8d0bd6ad8e67a820c09505117f5d386fd40 |
Malware sample hash |
| SHA-256 | 67ccc12c0a17dc31388a8c851d076edaaf1213e80398b01d46f5a29b8c7b8b9b |
Malware sample hash |
| SHA-256 | e8bc706b0b007d6a122c6b19e87451e550baee793540774db13b9a08803ed76a |
Malware sample hash |
| SHA-256 | f32dfbe4a2c11a975d735297bf76f6497ce9f5789ab8eaaef3fdd182c2f1f7b1 |
Malware sample hash |
| SHA-256 | c59ebe5cf45935c7b5f91b5936fe2c8a5feb7ca161e40ca4e3fb93e447373fa6 |
Malware sample hash |
| SHA-256 | 3537bfeaf2c18feafeaf773700a88118fd50979d97f2c42c7e34ba6c9aa62820 |
Malware sample hash |
| SHA-256 | 2949f0b16b83b35dc8a3dfa11815b9516403e3997e13100e7b86f3bb81f6c283 |
Malware sample hash |
| SHA-256 | 0e7c96a22e3612c68866a8693cc583df95972d3444978ce163c024a45682133a |
Malware sample hash |
| SHA-256 | 7d9f5eb3f704607e6f63681842f48071cc58f2f2e63b16b64a49440cb4b9e6e3 |
Malware sample hash |
| SHA-256 | 8a64d368ce14c5a1f5e775714bcc02f080d0541360743bb4235e0d640f1787b1 |
Malware sample hash |
| SHA-256 | 36cf87fe2e29cc8b0fd84fce91d70e62a4c4d2fc5f9650dc37440d629ae61b8f |
Malware sample hash |
| SHA-256 | 090e886e5605255ad5708e1f27aecc54319de835abd28853e54182981410707e |
Malware sample hash |
| SHA-256 | fa7d8c44a0ecb5ec40832d0d2cfe22c47879317177eae88d178e156f1c8d61a3 |
Malware sample hash |
| SHA-256 | d948b486c740b66642a5ae29dc1cb80da703ad40296bcda34a1b27216b63a5cd |
Malware sample hash |
| SHA-256 | 612fe3a3ace706725aa5415a1cd1cf18548627b4b40636c5443cb770def30b4c |
Malware sample hash |
| SHA-256 | 96488c59287889fcd3b9952ec78b78914fabb901c8b61a7354552439170ed148 |
Malware sample hash |
| Domain | rb[.]aliyuntsl[.]com |
Command-and-control or campaign infrastructure |
| Domain | br[.]team-c2[.]com |
Command-and-control or campaign infrastructure |
| Domain | hwlocal[.]team-hw[.]com |
Command-and-control or campaign infrastructure |
| Domain | br[.]team-hw[.]com |
Command-and-control or campaign infrastructure |
| Domain | data[.]mirrors-inc[.]com |
Command-and-control or campaign infrastructure |
| Domain | team-hw[.]com |
Command-and-control or campaign infrastructure |
| Domain | update[.]team-c2[.]com |
Command-and-control or campaign infrastructure |
| Domain | devops[.]aliyuntsl[.]com |
Command-and-control or campaign infrastructure |
| Domain | bageyi[.]kernel-lib[.]com |
Command-and-control or campaign infrastructure |
| Domain | 8yiu[.]kernel-lib[.]com |
Command-and-control or campaign infrastructure |
| Domain | dnslog[.]kernel-lib[.]com |
Command-and-control or campaign infrastructure |
| Domain | js[.]ai-jquery[.]com |
Command-and-control or campaign infrastructure |
| Domain | api[.]onlinevrgame[.]com |
Command-and-control or campaign infrastructure |
| Domain | file[.]ijjjst23m[.]com |
Command-and-control or campaign infrastructure |
| Domain | kerneltty[.]com |
Command-and-control or campaign infrastructure |
| Domain | 80[.]443[.]team |
Command-and-control or campaign infrastructure |
| Domain | up[.]443[.]team |
Command-and-control or campaign infrastructure |
| Domain | 404[.]443[.]team |
Command-and-control or campaign infrastructure |
| Domain | data[.]windows-update-cdn[.]com |
Command-and-control or campaign infrastructure |
| Domain | microsoft-azure-loadbalance[.]com |
Command-and-control or campaign infrastructure |
| Domain | update[.]aliyun[.]la |
Command-and-control or campaign infrastructure |
| Domain | api[.]gitlab[.]bet |
Command-and-control or campaign infrastructure |
| Domain | github[.]la |
Lookalike campaign domain |
| Domain | update[.]opentls2[.]com |
Command-and-control or campaign infrastructure |
| IP Address | 154[.]84[.]62[.]160 |
Campaign infrastructure |
| IP Address | 154[.]84[.]62[.]128 |
Campaign infrastructure |
| IP Address | 154[.]84[.]62[.]149 |
Campaign infrastructure |
| IP Address | 154[.]84[.]62[.]145 |
Campaign infrastructure |
| IP Address | 15[.]228[.]251[.]82 |
Campaign infrastructure |
| IP Address | 56[.]124[.]87[.]60 |
Campaign infrastructure |
| IP Address | 18[.]229[.]255[.]14 |
Campaign infrastructure |
| IP Address | 18[.]166[.]208[.]57 |
Campaign infrastructure |
| IP Address | 18[.]228[.]136[.]28 |
Campaign infrastructure |
| IP Address | 43[.]198[.]248[.]193 |
Campaign infrastructure |
| IP Address | 43[.]199[.]133[.]195 |
Campaign infrastructure |
| IP Address | 18[.]166[.]243[.]179 |
Campaign infrastructure |
| IP Address | 18[.]164[.]116[.]24 |
Campaign infrastructure |
| IP Address | 13[.]203[.]9[.]172 |
Campaign infrastructure |
| IP Address | 43[.]198[.]30[.]170 |
Campaign infrastructure |
| IP Address | 18[.]162[.]210[.]53 |
Campaign infrastructure |
| IP Address | 56[.]125[.]218[.]234 |
Campaign infrastructure |
| IP Address | 18[.]228[.]195[.]216 |
Campaign infrastructure |
| IP Address | 56[.]124[.]49[.]89 |
Campaign infrastructure |
| IP Address | 54[.]207[.]196[.]189 |
Campaign infrastructure |
| IP Address | 165[.]22[.]101[.]200 |
Campaign infrastructure |
| IP Address | 172[.]80[.]8[.]202 |
Campaign infrastructure |
| IP Address | 104[.]206[.]37[.]134 |
Campaign infrastructure |
| IP Address | 108[.]187[.]28[.]158 |
Campaign infrastructure |
| IP Address | 202[.]146[.]222[.]18 |
Campaign infrastructure |
| IP Address | 192[.]253[.]229[.]23 |
Campaign infrastructure |
| IP Address | 16[.]162[.]255[.]92 |
Campaign infrastructure |
| IP Address | 13[.]250[.]18[.]158 |
Campaign infrastructure |
| IP Address | 18[.]163[.]182[.]231 |
Campaign infrastructure |
| IP Address | 204[.]16[.]172[.]106 |
Campaign infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.