← BACK TO FEED
TAG

seo fraud1 article

Chinese Threat Actor Is Quietly Hijacking Brazilian Government Websites to Rank Gambling Pages

A Chinese-speaking cybercrime group called Gambling Goblin (linked to Earth Berberoka) has been compromising Brazilian government and educational web servers since mid-2025, installing malicious Apache modules that silently redirect visitors to fake app stores promoting illegal online gambling and sports betting. The primary objective appears to be large-scale SEO manipulation, exploiting the high-reputation domains of legitimate government sites to artificially boost search rankings for gambling pages, with over 630,000 URLs reportedly generated across hijacked Brazilian government subdomains. The group deploys a sophisticated toolkit including backdoors, a RAT, credential stealers, and an SSH brute-forcer, and it is part of a broader trend of China-aligned actors using similar server-hijacking techniques — mirroring a parallel campaign by a separate group called GhostRedirector that targeted IIS servers across Brazil, Thailand, and Vietnam.

3 Sept 2026