hacker-news · Crawled Sep 2, 2026

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

1 IoCs 2 Actors 1 Malware
Read original article ↗

AI Summary

A Chinese-speaking cybercrime group dubbed Gambling Goblin has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules to redirect traffic to online gambling and sports betting pages. The attack infrastructure uses compromised high-reputation .gov.br and .jus.br domains to manipulate search engine rankings through SEO fraud. The group deploys tools including DownPro, AlphaAgent, oRAT, a 3snake-based credential stealer, and an SSH brute-forcer. Check Point links the group to Earth Berberoka, previously documented by Trend Micro, and notes the use of reverse-proxy techniques to serve malicious content while preserving the appearance of legitimate traffic.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo 3snake Details →