Chinese-speaking cybercrime group targets Brazilian government sites for SEO manipulation and phishing.

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Research by: Amit Yardeni

A New Threat Landscape: Gambling Goblin Targets Brazil

In a significant shift in the cyber threat landscape, Check Point Research has identified a Chinese-speaking cybercrime group, dubbed Gambling Goblin, that has been actively targeting Brazilian organizations since mid-2025. This group is linked to Earth Berberoka, a previously documented actor known for its attacks on gambling sites across Asia. The emergence of Gambling Goblin marks a departure from Brazil’s typical home-grown banking trojan threats, indicating a new wave of foreign cybercriminal activity in the region. The full details of this operation can be explored further in the research published by Check Point.

Technical Insights into the Operation

The attackers have employed a sophisticated approach, compromising web servers and transforming them into stealthy proxies. By installing malicious Apache modules, they redirect legitimate traffic to phishing pages that masquerade as trusted app stores, including Google Play and the Microsoft Store. This tactic not only facilitates large-scale SEO manipulation but also allows the group to hijack traffic from high-reputation domains, many of which belong to Brazilian government sites.

Once inside a victim’s network, the group deploys a broad and heavily obfuscated Linux toolkit. This includes a custom downloader known as DownPro, multiple backdoors such as AlphaAgent and oRAT, and various reconnaissance tools. The obfuscation techniques employed are designed to slow down analysis and evade detection, making it challenging for security teams to respond effectively.

The Scale of the Operation

The operation’s reach extends beyond Brazil, with parallel phishing networks identified in Vietnamese, Spanish, and English. This suggests that the model is not only scalable but also adaptable to different regions. The infrastructure is capable of generating fresh domains daily, allowing the group to maintain a persistent presence and evade detection by security measures.

One of the most alarming aspects of this operation is its potential for escalation. The phishing pages already mimic legitimate app-download destinations, meaning that with a single configuration change, the same infrastructure could be used to deliver malware directly to victims. This latent risk highlights the need for heightened vigilance among organizations, particularly those in the public sector.

Conclusion: A Call to Action

The emergence of Gambling Goblin underscores a critical evolution in the cyber threat landscape, particularly in Brazil, which has become a lucrative target for cybercriminals due to its rapidly growing online betting market. The combination of a vast mobile user base and a plethora of under-secured web servers creates an ideal environment for such operations. As this group continues to exploit trusted infrastructure, it is imperative for organizations to bolster their defenses by patching exposed services, auditing configurations, and actively monitoring for rogue modules and processes.

Failure to address these vulnerabilities could result in further exploitation, not only of individual users but also of government institutions that lend credibility to these malicious operations. The time for action is now, as the line between cybercrime and advanced persistent threats continues to blur.

Read more about this research by Check Point.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cybercriminals Employ Diverse Scams to Deceive Victims into Sending Money via Untraceable Methods

Cybercriminals are increasingly employing a variety of scams to deceive victims into sending money through untraceable methods. According to the Consumer Financial Protection Bureau,...

GCC Central Banks Enhance Cybersecurity and Fintech Cooperation at Recent Meeting

A preparatory committee for the Gulf Cooperation Council (GCC) central bank governors convened virtually to enhance regional cooperation on payment systems, banking supervision, financial...

AI’s Growing Role in Cybersecurity Highlights the Importance of Human Judgment

As artificial intelligence (AI) continues to evolve, its integration into cybersecurity operations is reshaping how security teams function. According to reporting by CyberScoop, AI...

CISA Adds CVE-2026-85046 to Known Exploited Vulnerabilities Database for Google Products

Advisory Number: AV26-883 Date: September 4, 2026 As of September 3, 2026, Google has identified vulnerabilities affecting its products, specifically noting that an exploit for CVE-2026-85046...