Security1 distinct publisher2 min readPublished
Check Point says a Chinese-speaking crew has been running custom Apache modules on compromised Brazilian federal, state and municipal web servers since mid-2025, so the address bar and the TLD tell a visitor nothing useful.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The detection guidance says most of what you need to know about how hard this is to find. Check Point tells defenders to audit installed Apache modules for unexpected .so files, especially ones timestamped to match legitimate modules such as mod_ssl or mod_suexec [12]. Matched timestamps defeat the usual first pass, which is sorting the module directory by modification date. What is left is diffing the loaded module list against the package manager's manifest on every public web host, which is inventory work most public-sector estates have not done once, let alone continuously.
The second signal is path-scoped. CPR says a sudden absence of Content-Security-Policy headers on specific URL paths is a strong indicator of injected reverse-proxy behaviour [13]. Specific paths is the operative phrase. The root of the site keeps its headers and its real content, while a chosen path proxies attacker-controlled phishing pages with no foreign domain in the browser bar [4]. Reputation feeds, TLD allowlists and root-URL crawlers all evaluate the domain, and the domain is a real government domain, held by real federal, state and municipal institutions [3]. Blocking therefore has to be per-URL or not at all, and taking a state agency host offline in a web filter carries its own bill.
The borrowed trust runs further than the compromised hosts themselves. App tiles and navigation links on the phishing pages point to dozens of genuine domains, the majority of them impersonating legitimate .gov.br sites [10]. Search ranking is the product; the gambling and sports betting traffic is the revenue [6].
On portability, Check Point found the same template already localised for Vietnamese, Spanish and English-speaking audiences, with infrastructure generating fresh domains daily [9]. Counting Brazil's Portuguese deployment, that is four language markets running off one template [18].
Separate the attribution from the telemetry. The tie to Earth Berberoka, a cluster previously documented against Asian gambling sites, rests on infrastructure overlap that includes a shared Amazon ASN previously linked to that group, plus generated domains traced back to Chinese-language gambling and adult-content sites [8][16]. Check Point presents that as overlap. It is not a confession, and no host count is published: the writeup says "many" .gov.br sites and "dozens" of referenced domains [19].
The detail I would weight over the SEO fraud: alongside the proxy modules, the same intrusions deploy a Linux toolkit with several backdoors, a credential stealer and a reconnaissance agent for mapping internet-facing infrastructure [7]. The betting redirect is the part a visitor sees. Check Point also notes the pages already imitate Google Play, Microsoft Store and Amazon closely enough that one configuration change would serve apps instead of bets [11].
Ranked by verification strength, evidence, and original report placement.
Check Point Research dubbed a Chinese-speaking cybercrime cluster "Gambling Goblin", which compromises trusted government websites and turns them into infrastructure for a fraud operation built to scale.
Check Point Research has been tracking the campaign as sustained and active since mid-2025.
The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state and municipal institutions.
The group installs custom Apache modules on compromised servers that quietly proxy visitors to attacker-controlled phishing pages without ever showing a foreign domain in the browser bar.
The malicious Apache modules also strip the server's security headers, clearing the way for injected scripts to run unrestricted.
The phishing pages impersonate Google Play, Microsoft Store and Amazon, complete with fabricated ratings and structured metadata, while actually pushing online gambling and sports betting.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
product
Pennsylvania's Snap case makes an App Store questionnaire the alleged lie1 distinct publisher
build
Wrapping a web tool in VS Code: four sandbox rules, and two gaps in the published fix1 distinct publisher
invest
Behind-the-meter gas is the data center buildout's real cost: 318 Mt a year1 distinct publisher
product
Swapping out the GPU leaves four more rack lines on Nvidia's invoice1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Mechanism is concrete, provenance is singular
The technical core would survive scrutiny: modules that reverse-proxy without changing the address bar, stripped Content-Security-Policy headers, .so files timestamped to imitate mod_ssl, a named toolkit of downloader, backdoors, stealer and scanner. What holds it up is that Check Point says so, alone, with the indicators parked in a separate report. Nobody in this reporting has looked at a compromised .gov.br host independently.
Real in the wild, unmeasured on the page
Something is genuinely running: a campaign dated to mid-2025, templates already localised for four language markets, domains minted daily. Against that, the size of the thing is given in adjectives. "Many" .gov.br sites and "dozens" of real domains is all a reader gets — no host count, no affected agency, no traffic figure — so the footprint can be confirmed as live but not as large.
The label outruns the ledger
"Espionage-grade", "blurs the line between cybercrime and APT", "one configuration change away from pushing malicious apps" — each of these reaches past what is actually shown, which is competent Linux crimeware serving betting ads through borrowed reputation. The named actor and the Earth Berberoka lineage add narrative weight that a single shared Amazon ASN does not carry. The gap is real but modest, because the underlying technique and the defender guidance are not inflated at all.
The finder sells the fix
Naming a threat actor is marketing as much as taxonomy, and this write-up ends by routing readers to Check Point's fuller report — the classic structure of research published by a company whose product line covers exactly the gap it describes. That does not make the Apache modules imaginary; it does mean the choice of adjectives, the actor branding, and the export-is-coming framing all serve the publisher, and no counterweight from a government body or rival lab appears in our coverage.
Believe the plumbing, hold the scale
Split the story in two and confidence splits with it. The server-side behaviour is described with the kind of specificity that gets checked and corrected quickly if wrong, so it deserves working trust. The parts that would let anyone judge how much this matters — how many hosts, which institutions, whose traffic, and whether Earth Berberoka is really the parent — remain a single vendor's assertion with no outside confirmation.