VMTech
Discuss a project

Malicious Apache modules redirect Brazilian public-sector web traffic

Malicious Apache modules redirect Brazilian public-sector web traffic

Check Point Research has identified a Chinese-speaking cybercrime cluster, tracked as Gambling Goblin, using malicious Apache modules on compromised web servers operated by Brazilian government and educational institutions. The modules divert visitors through attacker-controlled pages that promote online gambling and sports betting while the traffic continues to appear to come from the legitimate domain.

Check Point has tracked the campaign since mid-2025. It said the modules act as reverse proxies, sending visitors to phishing pages while stripping the compromised site’s security headers. The injected pages imitate trusted app-download destinations, including Google Play, Microsoft Store and Amazon, before presenting gambling content.

Compromised sites used to manipulate visibility

Check Point assessed that the likely objective is search-engine optimization manipulation at scale. High-reputation domains, including many Brazilian government sites, can be linked together to inflate search rankings. The company did not state whether betting sites promoted through the compromised servers are licensed under Brazil’s fixed-odds betting rules.

Brazil began licensing fixed-odds betting on January 1, 2025, under Law 14,790/2023. Authorized operators use .bet.br domains issued through Registro.br. The campaign’s use of public-sector domains does not establish that the promoted betting operations are authorized.

ANY.RUN reported in July that at least 20 .gov.br portals belonging to Brazilian municipalities and police forces had been used to distribute malware in a campaign it calls PhantomEnigma. It cautioned that compromised government hosts form part of the delivery chain rather than confirmed attacker-controlled infrastructure, so broad blocking could interfere with access to public services.

Linux tools and missing detection indicators

Once on a server, Gambling Goblin deploys DownPro, the custom downloader AlphaAgent, the modular backdoor oRAT, a remote-access trojan, a 3snake-based credential stealer, an SSH brute-forcer and a plugin-driven reconnaissance agent. Check Point has not directly observed the group’s initial-access method.

The public 3snake version attaches ptrace to newly spawned sshd and sudo processes and extracts strings related to password-based authentication. Its documentation says it targets rooted servers, meaning credentials used to administer an affected host can be exposed to an operator-controlled component.

Published material does not include a number of compromised servers or module filenames, paths and hashes that administrators could use to identify malicious modules loaded by Apache. Check Point also found Vietnamese, Spanish and English phishing networks, plus infrastructure that generates domains daily. It warned that the app-store lures leave the operators close to distributing malware directly to visitors.

Related server-side SEO fraud

The activity follows other cases in which compromised servers were used to alter search visibility. ESET documented at least 65 Windows servers, mainly in Brazil, Thailand and Vietnam, compromised in June 2025 by GhostRedirector, which installed the native IIS module Gamshen. ESET said Gamshen changed responses for Googlebot while ordinary visitors received the requested page.

For businesses operating Apache infrastructure, the practical implication is to investigate unexpected loaded modules, reverse-proxy behavior and removed security headers as signs of possible compromise. Response plans should preserve access to essential public services while separating affected hosts from attacker-controlled infrastructure and reviewing administrative credentials.

#cybersecurity#apache#websecurity#malware
Open analytics
On the site 0 views
min read 4 02.09.2026
Instagram

Malicious Apache modules redirect Brazilian public-sector web traffic

Open the post on Instagram ↗