A cybercrime group known as Gambling Goblin has been infiltrating web servers operated by Brazilian government and educational institutions. By installing malicious Apache modules, they redirect visitors to gambling and sports betting pages. These fake pages are cleverly disguised as legitimate app stores like Google Play and Microsoft Store. Check Point Research has been monitoring this operation since mid-2025, noting that the attackers aim to manipulate search engine results by exploiting the high reputation of these compromised domains. This tactic inflates the search rankings of their gambling sites.
The impact of this campaign is significant, with at least 20 government-related portals in Brazil being utilized to spread malware. However, affected government systems are not the intended targets; they are merely part of the delivery chain. Blocking these compromised servers indiscriminately could disrupt access to essential government resources. Despite the Brazilian government beginning to license fixed-odds betting in 2025, it remains unclear whether the gambling sites promoted through these compromised servers are authorized.
The cybercriminals use advanced tools like 3snake, which can extract authentication details from compromised servers. Yet, the exact method they use to gain initial access remains unknown. Additional investigations reveal that similar phishing networks have been found in languages like Vietnamese, Spanish, and English. These networks create new domains daily, staying one step ahead in their malicious activities. No specific organizations have been named as affected, and there is no confirmation on whether the compromised servers have been cleaned up. The group has been linked to Earth Berberoka, a cluster known for targeting gambling sites in Asia.
An ESET report from June 2025 noted that GhostRedirector, likely aligned with Chinese interests, compromised 65 Windows servers in Brazil and other countries. This group developed a malicious IIS module called Gamshen, aimed at SEO fraud, promoting gambling websites by altering server responses only when accessed by Googlebot. This technique has also been documented by Palo Alto Networks and Hunt.io. The latter found over 630,000 URLs on hijacked Brazilian subdomains, serving up keyword-stuffed pages to Googlebot while redirecting real users to gambling sites. The ongoing investigation remains coordinated with Brazil's government incident response team.


