← BACK TO FEED
TAG

brazil2 articles

Chinese Threat Actor Is Quietly Hijacking Brazilian Government Websites to Rank Gambling Pages

A Chinese-speaking cybercrime group called Gambling Goblin (linked to Earth Berberoka) has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules that silently redirect visitors to fake app stores promoting illegal online gambling and sports betting. The primary objective appears to be large-scale SEO manipulation, exploiting the high-reputation domains of legitimate government sites to artificially boost search rankings for gambling pages, with over 630,000 URLs reportedly generated across hijacked Brazilian government subdomains. The group deploys a sophisticated toolkit including backdoors, a RAT, credential stealers, and an SSH brute-forcer, and it is part of a broader trend of China-aligned actors using similar server-hijacking techniques — mirroring a parallel campaign by a separate group called GhostRedirector that targeted IIS servers across Brazil, Thailand, and Vietnam.

3 Sept 2026

Brazilian Gov Websites Hijacked to Deliver Malware in Active Banking Campaign

A cyberattack campaign called PhantomEnigma has compromised more than 20 Brazilian government websites, turning them into malware delivery channels targeting banks and public agencies. The operation uses fake police-themed documents sent via authenticated emails and trusted `.gov.br` domains to deceive victims into installing a modular backdoor capable of stealing credentials, establishing persistence, and delivering additional payloads. The campaign's abuse of legitimate government infrastructure and rotating command-and-control domains makes it particularly difficult to detect using conventional security tools, with behavioral analysis recommended as a more reliable defence.

19 Jul 2026